Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2022-41248MEDIUMJenkins BigPanda Notifier Plugin 1.4.0 and earlier does not mask the BigPanda API key on the global configuration form, increasing the potenEPSS 0.4%CVE-2022-45897MEDIUMOn Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored clearteEPSS 0.4%CVE-2019-16638HIGHAn issue was found on the Ruijie EG-2000 series gateway. An attacker can easily dump cleartext stored passwords in /data/config.text with siEPSS 0.4%CVE-2023-51702MEDIUMApache Airflow CNCF Kubernetes provider, Apache Airflow: Kubernetes configuration file saved without encryption in the Metadata and logged as plain text in the Triggerer serviceEPSS 0.4%CVE-2022-42956HIGHThe PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain the cleartext master password.EPSS 0.4%CVE-2022-42955HIGHThe PassWork extension 5.0.9 for Chrome and other browsers allows an attacker to obtain cleartext cached credentials.EPSS 0.4%CVE-2023-27098HIGHTP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.EPSS 0.4%CVE-2026-83551HIGHCleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline pathEPSS 0.4%CVE-2023-32983MEDIUMJenkins Ansible Plugin 204.v8191fd551eb_f and earlier does not mask extra variables displayed on the configuration form, increasing the poteEPSS 0.4%CVE-2023-32982MEDIUMJenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller wEPSS 0.4%CVE-2025-27685HIGHVasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & PriEPSS 0.4%CVE-2023-49341HIGHAn issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive EPSS 0.4%CVE-2024-55196HIGHInsufficiently Protected Credentials in the Mail Server Configuration in GoPhish v0.12.1 allows an attacker to access cleartext passwords foEPSS 0.4%CVE-2024-31840MEDIUMAn issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated EPSS 0.4%CVE-2023-41335LOWTemporary storage of plaintext passwords during password changes in matrix synapseEPSS 0.4%CVE-2024-13843MEDIUMCleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a EPSS 0.4%CVE-2023-3489HIGHfirmwaredownload command could log servers passwords in clear textEPSS 0.4%CVE-2025-55334MEDIUMWindows Kernel Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2024-47529MEDIUMOpenC3 COSMOS uses clear text storage of password/token (`GHSL-2024-129`)EPSS 0.4%CVE-2025-59102MEDIUMSecrets Stored in Plaintext in Database in dormakaba access managerEPSS 0.4%