Falhas do tipo CWE-312

465 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2024-31486MEDIUMA vulnerability has been identified in OPUPI0 AMQP/MQTT (All versions < V5.30). The affected devices stores MQTT client passwords without suEPSS 0.5%CVE-2022-39364MEDIUMException logging in Sharepoint app reveals clear-text connection detailsEPSS 0.5%CVE-2021-35036MEDIUMA cleartext storage of information vulnerability in the Zyxel VMG3625-T50B firmware version V5.50(ABTL.0)b2k could allow an authenticated atEPSS 0.5%CVE-2022-24188HIGHThe /device/signin end-point for the Ourphoto App version 1.4.1 discloses clear-text password information for functionality within the pictuEPSS 0.5%CVE-2024-24375HIGHSQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.EPSS 0.5%CVE-2023-45151MEDIUMOAuth2 client_secret stored in plain text in the Nextcloud databaseEPSS 0.5%CVE-2026-15065CRITICALVulnerabilities in IBM AIX and PowerVM VIOSEPSS 0.5%CVE-2023-23944LOWNexcloud Mail app temporarily stores cleartext password in databaseEPSS 0.5%CVE-2022-41933MEDIUMPlaintext storage of password in org.xwiki.platform:xwiki-platform-security-authentication-defaultEPSS 0.5%CVE-2024-36497CRITICALUnhashed Storage of PasswordEPSS 0.5%CVE-2021-29481MEDIUMClient side sessions should not allow unencrypted storageEPSS 0.5%CVE-2023-22584HIGHCleartext credentials in Danfoss AK-EM100EPSS 0.5%CVE-2022-48073HIGHPhicomm K2G v22.6.3.20 was discovered to store the root and admin passwords in plaintext.EPSS 0.5%CVE-2024-28387HIGHAn issue in axonaut v.3.1.23 and before allows a remote attacker to obtain sensitive information via the log.txt component.EPSS 0.4%CVE-2020-8276The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the useEPSS 0.4%CVE-2024-41716HIGHCleartext storage of sensitive information vulnerability exists in WindLDR and WindO/I-NV4. If this vulnerability is exploited, an attacker EPSS 0.4%CVE-2022-48071HIGHPhicomm K2 v22.6.534.263 was discovered to store the root and admin passwords in plaintext.EPSS 0.4%CVE-2023-0690MEDIUMBoundary Workers Store Rotated Credentials in Plaintext Even When a Key Management Service ConfiguredEPSS 0.4%CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%CVE-2024-58277HIGHR Radio Network FM Transmitter 1.07 System Settings DisclosureEPSS 0.4%