Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2025-59409HIGHFlock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartexEPSS 0.3%CVE-2024-40582HIGHPentaminds CuroVMS v2.0.1 was discovered to contain exposed sensitive information.EPSS 0.3%CVE-2026-27877MEDIUMPublic dashboards discloses all direct mode datasourcesEPSS 0.3%CVE-2024-51175HIGHAn issue in H3C switch h3c-S1526 allows a remote attacker to obtain sensitive information via the S1526.cfg component.EPSS 0.3%CVE-2023-27243HIGHAn access control issue in Makves DCAP v3.0.0.122 allows unauthenticated attackers to obtain cleartext credentials via a crafted web requestEPSS 0.3%CVE-2023-2335MEDIUMPlaintext Password in RegistryEPSS 0.3%CVE-2025-25758HIGHAn issue in KukuFM Android v1.12.7 (11207) allows attackers to access sensitive cleartext data via the android:allowBackup="true" in the ANdEPSS 0.3%CVE-2025-8528MEDIUMExrick xboot getMenuList sensitive information in a cookieEPSS 0.3%CVE-2025-59792MEDIUMApache Kvrocks: MONITOR command reveals plaintext credentials to non-adminsEPSS 0.3%CVE-2025-51055HIGHInsecure Data Storage of credentials has been found in /api_vedo/configuration/config.yml file in Vedo Suite version 2024.17. This file contEPSS 0.3%CVE-2022-35279MEDIUM"IBM Business Automation Workflow 18.0.0.0, 18.0.0.1, 18.0.0.2, 19.0.0.1, 19.0.0.2, 19.0.0.3, 20.0.0.1, 20.0.0.2, 21.0.2, 21.0.3, and 22.0.1EPSS 0.3%CVE-2025-65826CRITICALThe mobile application was found to contain stored credentials for the network it was developed on. If an attacker retrieved this, and foundEPSS 0.3%CVE-2024-46505CRITICALInfoblox BloxOne v2.4 was discovered to contain a business logic flaw due to thick client vulnerabilities.EPSS 0.3%CVE-2024-11159MEDIUMUsing remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3EPSS 0.3%CVE-2024-34891MEDIUMInsufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read Exchange aEPSS 0.3%CVE-2025-4537LOWyangzongzhuan RuoYi-Vue Password login.vue sensitive information in a cookieEPSS 0.3%CVE-2019-14886MEDIUMA vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_securitEPSS 0.3%CVE-2022-22302MEDIUMA clear text storage of sensitive information (CWE-312) vulnerability in both FortiGate version 6.4.0 through 6.4.1, 6.2.0 through 6.2.9 andEPSS 0.3%CVE-2020-11918MEDIUMAn issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on aEPSS 0.3%CVE-2025-30124CRITICALAn issue was discovered on Marbella KR8s Dashcam FF 2.0.8 devices. When a new SD card is inserted into the dashcam, the existing password isEPSS 0.3%