Falhas do tipo CWE-312

468 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (senhas, tokens, chaves criptográficas, PII) através de canais inseguros, logs, mensagens de erro verbosas ou armazenamento inadequado. O risco é que um atacante ou observador não autorizado capture essas informações e as use para comprometer a segurança do sistema ou dos usuários.

Exemplo

Uma API retorna stacktrace completo em resposta de erro, revelando caminhos internos do servidor; uma aplicação escreve senhas em plain text nos logs; credenciais são transmitidas via HTTP em vez de HTTPS; tokens de autenticação ficam expostos no histórico do browser ou em variáveis de ambiente visíveis.

Como mitigar

Nunca exponha dados sensíveis em mensagens de erro, logs ou respostas HTTP — use apenas IDs de erro genéricos. Sempre transmita credenciais por canais criptografados (TLS/HTTPS). Armazene segredos em vaults (HashiCorp Vault, AWS Secrets Manager) e nunca em código, configurações ou logs. Revise regularmente logs, caches e históricos para remover informações classificadas.

CVE-2024-33471HIGHAn issue in the Sensor Settings of AVTECH Room Alert 4E v4.4.0 allows attackers to gain access to SMTP credentials in plaintext via a crafteEPSS 0.3%CVE-2024-29956MEDIUMcleartext password in supportsave logs when a user schedules a switch Supportsave from Brocade SANnavEPSS 0.3%CVE-2023-48707MEDIUMCleartext Storage of Sensitive Information in codeigniter4/shieldEPSS 0.3%CVE-2025-7426CRITICALMINOVA TTA Information Disclosure and Credential ExposureEPSS 0.3%CVE-2019-3937Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, slideshow passcode, and other configuratEPSS 0.3%CVE-2026-31848HIGHReversible ecos_pw Cookie Allows Authentication Bypass in Nexxt Nebula 300+EPSS 0.3%CVE-2026-25751CRITICALFUXA Unauthenticated Exposure of Plaintext Database CredentialsEPSS 0.3%CVE-2024-42451HIGHA vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by caEPSS 0.3%CVE-2025-12772HIGHPlaintext Switch admin login password is seen in Brocade SANnav support saveEPSS 0.3%CVE-2024-23584MEDIUMHCL BigFix Asset Discovery is affected by a security vulnerabilityEPSS 0.3%CVE-2025-23027MEDIUMBASEHUB_TOKEN commited in next-forgeEPSS 0.3%CVE-2025-53672MEDIUMJenkins Kryptowire Plugin 0.2 and earlier stores the Kryptowire API key unencrypted in its global configuration file on the Jenkins controllEPSS 0.3%CVE-2022-45787MEDIUMApache James MIME4J: Temporary File Information Disclosure in MIME4J TempFileStorageProviderEPSS 0.3%CVE-2025-0142MEDIUMZoom Jenkins Marketplace plugin - Cleartext Storage of Sensitive InformationEPSS 0.3%CVE-2020-14480MEDIUMDue to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to cerEPSS 0.3%CVE-2025-2120LOWThinkware Car Dashcam F800 Pro Configuration File hostapd.conf cleartext storage in a file or on diskEPSS 0.3%CVE-2025-62261MEDIUMLiferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92EPSS 0.3%CVE-2020-25678A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching thEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%CVE-2024-46383LOWHathway Skyworth Router CM5100-511 v4.1.1.24 was discovered to store sensitive information about USB and Wifi connected devices in plaintextEPSS 0.3%