Falhas do tipo CWE-347

534 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2025-25292CRITICALRuby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)EPSS 63.8%CVE-2025-59718CRITICALA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiEPSS 63.4%KEVCVE-2013-3900MEDIUMWinVerifyTrust Signature Validation VulnerabilityEPSS 44.6%KEVCVE-2018-0114A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens uEPSS 42.7%CVE-2020-1464HIGHWindows Spoofing VulnerabilityEPSS 41.1%KEVCVE-2024-9487CRITICALAn Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabledEPSS 25.1%CVE-2025-59719CRITICALAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 tEPSS 25.0%CVE-2025-25291CRITICALruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)EPSS 19.5%CVE-2024-45607MEDIUMwhatsapp-api-js fails to validate message's signatureEPSS 14.5%CVE-2026-48558CRITICALSimpleHelp Authentication Bypass via Missing OIDC JWT Signature VerificationEPSS 11.5%CVE-2026-40372CRITICALASP.NET Core Elevation of Privilege VulnerabilityEPSS 11.2%CVE-2024-45409CRITICALThe Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectorEPSS 10.7%CVE-2025-29775CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue CommentEPSS 9.4%CVE-2025-29774CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo ReferencesEPSS 9.0%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.0%CVE-2020-9047MEDIUMexacqVision Software - Improper Verification of Cryptographic SignatureEPSS 7.8%CVE-2026-29000CRITICALpac4j-jwt JwtAuthenticator Authentication BypassEPSS 5.9%CVE-2020-2021CRITICALPAN-OS: Authentication Bypass in SAML AuthenticationEPSS 4.4%KEVCVE-2025-47827MEDIUMIn IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. UltimaEPSS 4.0%KEVCVE-2026-10795HIGHUpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpcEPSS 3.6%