Falhas do tipo CWE-347

640 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-44714HIGHbitcoinj: ScriptExecution P2PKH/P2WPKH Verification BypassEPSS 0.3%CVE-2025-29915HIGHSuricata af-packet: defrag option can lead to truncated packets affecting visibilityEPSS 0.3%CVE-2026-32597HIGHPyJWT accepts unknown `crit` header extensions (RFC 7515 §4.1.11 MUST violation)EPSS 0.3%CVE-2023-25934MEDIUM DELL ECS prior to 3.8.0.2 contains an improper verification of cryptographic signature vulnerability. A network attacker with an ability toEPSS 0.3%CVE-2026-36721CRITICALA lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authenticatioEPSS 0.3%CVE-2024-7481HIGHImproper signature verification of Printer driver installation in TeamViewer Remote ClientsEPSS 0.3%CVE-2026-45755MEDIUMSymfony: Mailtrap Mailer Webhook Parser Never Verifies the X-Mt-Signature HMAC — Unauthenticated Webhook Event InjectionEPSS 0.3%CVE-2026-50634MEDIUMApache CXF: WS JSON request filter trusts metadata from an unvalidated first signature entryEPSS 0.3%CVE-2022-31123MEDIUMGrafana plugin signature bypass vulnerabilityEPSS 0.3%CVE-2026-49998HIGHCentrifugo: Dynamic JWKS key cache keyed only by `kid` allows cross-issuer JWT authentication bypassEPSS 0.3%CVE-2026-44104CRITICALControllerAgent does not perform validation of firmwareEPSS 0.3%CVE-2023-42811MEDIUMAEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEPSS 0.3%CVE-2019-1811MEDIUMCisco NX-OS CLI Command Software Image Signature Verification VulnerabilitiesEPSS 0.3%CVE-2026-40941HIGHCacti: Package Import Signature Validation Bypass Allows Self-Signed PackagesEPSS 0.3%CVE-2026-48758MEDIUMsigstore-js: DSSE payloadType type-binding failureEPSS 0.3%CVE-2026-34840HIGHOneUptime SSO: Multi-Assertion Identity Injection via Decoupled Signature VerificationEPSS 0.3%CVE-2024-23960MEDIUMAlpine Halo9 Improper Verification of Cryptographic Signature VulnerabilityEPSS 0.3%CVE-2019-1810MEDIUMCisco Nexus 3000 Series and 9000 Series Switches in NX-OS Mode CLI Command Software Image Signature Verification VulnerabilityEPSS 0.3%CVE-2026-6966HIGHSignature Threshold Bypass in awslabs/tough Delegated RolesEPSS 0.3%CVE-2026-45795MEDIUMJanssen Project: JWE Request Object Signature Verification Bypass in jans-auth-serverEPSS 0.3%