Falhas do tipo CWE-347

640 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-28802HIGHAuthlib: Setting `alg: none` and a blank signature appears to bypass signature verificationEPSS 0.4%CVE-2026-54782CRITICALCoreWCF: Authentication bypass in CoreWCF SAML 1.1 / 2.0 token signature validationEPSS 0.4%CVE-2022-23334CRITICALThe Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackersEPSS 0.4%CVE-2024-7479HIGHImproper signature verification of VPN driver installation in TeamViewer Remote ClientsEPSS 0.4%CVE-2025-12295HIGHD-Link DAP-2695 Firmware Update sub_40C6B8 signature verificationEPSS 0.4%CVE-2021-1461MEDIUMCisco SD-WAN Software Signature Verification Bypass VulnerabilityEPSS 0.4%CVE-2025-27670CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Insufficient Signature Validation OEPSS 0.4%CVE-2024-21383LOWMicrosoft Edge (Chromium-based) Spoofing VulnerabilityEPSS 0.4%CVE-2002-1796HIGHChaiVM EZloader for HP color LaserJet 4500 and 4550 and HP LaserJet 4100 and 8150 does not properly verify JAR signatures for new services, EPSS 0.4%CVE-2023-49646MEDIUMImproper authentication in some Zoom clients before version 5.16.5 may allow an authenticated user to conduct a denial of service via networEPSS 0.4%CVE-2025-32977CRITICALQuest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 EPSS 0.4%CVE-2024-47832CRITICALXML Signature Bypass via differential XML parsing in ssoreadyEPSS 0.4%CVE-2023-49079CRITICALMisskey's missing signature validation allows arbitrary users to impersonate any remote user.EPSS 0.4%CVE-2022-47549MEDIUMAn unprotected memory-access operation in optee_os in TrustedFirmware Open Portable Trusted Execution Environment (OP-TEE) before 3.20 allowEPSS 0.4%CVE-2021-31847HIGHImproper privilege management in repair process of MA for WindowsEPSS 0.4%CVE-2025-54982CRITICALSAML 2.0 Public Key Validation IssueEPSS 0.4%CVE-2026-48526HIGHPyJWT: Public-key JWK accepted as HMAC secret enables forged HS256 tokens when mixed families are allowedEPSS 0.4%CVE-2026-19505CRITICALRDK-B WebUI improper cryptographic signature verification vulnerabilityEPSS 0.4%CVE-2024-54150HIGHAlgorithm Confusion Vulnerability in cjwtEPSS 0.4%CVE-2023-28801CRITICALImproper SAML signature verificationEPSS 0.4%