Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2023-28713HIGHPlaintext storage of a password exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. Because account information of the database isEPSS 0.4%CVE-2022-2813MEDIUMSourceCodester Guest Management System cleartext storageEPSS 0.4%CVE-2022-2805MEDIUMA flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allowsEPSS 0.4%CVE-2024-32474HIGHSentry's superuser cleartext password leaked in logsEPSS 0.4%CVE-2023-31408MEDIUMCleartext Storage of Sensitive Information in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116, 112252EPSS 0.4%CVE-2022-34339MEDIUM"IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-FEPSS 0.4%CVE-2023-44159MEDIUMSensitive information disclosure due to cleartext storage of sensitive information. The following products are affected: Acronis Cyber ProteEPSS 0.4%CVE-2020-36887HIGHSpinetiX Fusion Digital Signage 3.4.8 Unauthenticated Database Backup DisclosureEPSS 0.4%CVE-2023-22949MEDIUMAn issue was discovered in TigerGraph Enterprise Free Edition 3.x. There is logging of user credentials. All authenticated GSQL access requeEPSS 0.4%CVE-2021-42066SAP Business One - version 10.0, allows an admin user to view DB password in plain text over the network, which should otherwise be encrypteEPSS 0.4%CVE-2023-50957HIGHIBM Storage Defender - Resiliency Service privilege escalationEPSS 0.4%CVE-2022-38112HIGHSensitive Information Disclosure VulnerabilityEPSS 0.4%CVE-2020-6980Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versionsEPSS 0.4%CVE-2023-48700MEDIUMClear Text Credentials Exposed via Onboarding TaskEPSS 0.4%CVE-2023-29480HIGHRibose RNP before 0.16.3 sometimes lets secret keys remain unlocked after use.EPSS 0.4%CVE-2021-22929An information disclosure exists in Brave Browser Desktop prior to version 1.28.62, where logged warning messages that included timestamps oEPSS 0.4%CVE-2023-2809HIGHUse of Cleartext credentials in Sage 200 SpainEPSS 0.4%CVE-2023-30528MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potentEPSS 0.4%CVE-2023-30531MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasinEPSS 0.4%CVE-2024-22084HIGHAn issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed throughEPSS 0.4%