Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2026-42151HIGHPrometheus Azure AD remote write OAuth client secret exposed via config APIEPSS 0.4%CVE-2023-6874HIGHZigbee Unauthenticated DoS via NWK Sequence number manipulationEPSS 0.4%CVE-2022-20660MEDIUMCisco IP Phones Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-36790HIGHNetgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 was discovered to store credentials in plaintext.EPSS 0.3%CVE-2024-52525LOWNextcloud Server User password is available in memory of the PHP processEPSS 0.3%CVE-2025-34200HIGHVasion Print (formerly PrinterLogic) Network Account Password Stored in CleartextEPSS 0.3%CVE-2024-7783MEDIUMImproper Storage of Sensitive Information in Bearer Token in mintplex-labs/anything-llmEPSS 0.3%CVE-2024-46340CRITICALTL-WR845N(UN)_V4_201214, TP-Link TL-WR845N(UN)_V4_200909, and TL-WR845N(UN)_V4_190219 was discovered to transmit user credentials in plainteEPSS 0.3%CVE-2025-26495HIGHSensitive Data Exposure in Tableau ServerEPSS 0.3%CVE-2024-8459HIGHPLANET Technology switch devices - Cleartext storage of SNMPv3 users' passwordsEPSS 0.3%CVE-2023-27370MEDIUMNETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure VulnerabilityEPSS 0.3%CVE-2025-27623MEDIUMJenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via RESTEPSS 0.3%CVE-2023-25596MEDIUMAuthenticated Sensitive Information Disclosure in ClearPass Policy ManagerEPSS 0.3%CVE-2024-43429MEDIUMMoodle: user information visibility control issues in gradebook reportsEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2026-33026CRITICALnginx-ui Backup Restore Allows Tampering with Encrypted BackupsEPSS 0.3%CVE-2023-30530MEDIUMJenkins Consul KV Builder Plugin 2.0.13 and earlier stores the HashiCorp Consul ACL Token unencrypted in its global configuration file on thEPSS 0.3%CVE-2023-30527MEDIUMJenkins WSO2 Oauth Plugin 1.0 and earlier stores the WSO2 Oauth client secret unencrypted in the global config.xml file on the Jenkins contrEPSS 0.3%CVE-2022-21818MEDIUMNVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after siEPSS 0.3%CVE-2023-28345MEDIUMAn issue was discovered in Faronics Insight 10.0.19045 on Windows. The Insight Teacher Console application exposes the teacher's Console pasEPSS 0.3%