Falhas do tipo CWE-347

640 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2024-36277MEDIUMImproper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iEPSS 0.3%CVE-2026-87802CRITICALApache Syncope: SRA OAuth2 JWT signature verification bypassEPSS 0.3%CVE-2026-23518CRITICALFleet has a JWT signature bypass vulnerability in Azure AD MDM enrollmentEPSS 0.3%CVE-2026-62757MEDIUMWindows Schannel Security Feature Bypass VulnerabilityEPSS 0.3%CVE-2026-34377HIGHZebra has a Consensus Failure due to Improper Verification of V5 TransactionsEPSS 0.3%CVE-2026-7511MEDIUMPKCS7_verify signer confusion allows forged signatures to be acceptedEPSS 0.3%CVE-2026-11348HIGHAuthentication Bypass in HAVELSAN's Open Source Project Liman MYSEPSS 0.3%CVE-2026-6911CRITICALAuthentication Bypass via Missing JWT Signature Verification in AWS Ops WheelEPSS 0.3%CVE-2026-41301MEDIUMOpenClaw 2026.3.22 < 2026.3.31 - Forged Nostr DM Pairing State Creation via Signature Verification BypassEPSS 0.3%CVE-2026-52754HIGHGhidra < 12.1 - Authentication Bypass via Null Signature in PKIAuthenticationModuleEPSS 0.3%CVE-2021-3633HIGHA DLL preloading vulnerability was reported in Lenovo Driver Management prior to version 2.9.0719.1104 that could allow privilege escalationEPSS 0.3%CVE-2026-24032MEDIUMA vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weaEPSS 0.3%CVE-2025-2764HIGHCarlinKit CPC200-CCPA update.cgi Improper Verification of Cryptographic Signature Code Execution VulnerabilityEPSS 0.3%CVE-2026-59163CRITICALMnemosyne has JWT signature verification bypass sync server that allows authentication bypassEPSS 0.3%CVE-2024-10237HIGHSMC BMC Firmware Image Authentication Design IssueEPSS 0.2%CVE-2026-32974HIGHOpenClaw < 2026.3.12 - Forged Event Injection via Feishu Webhook Verification TokenEPSS 0.2%CVE-2023-40012MEDIUMuthenticode EKU validation bypassEPSS 0.2%CVE-2026-48747MEDIUMSymfony: Mailomat Mailer Webhook Parser Reads the HMAC Algorithm from the Request: Signature Algorithm DowngradeEPSS 0.2%CVE-2019-1736MEDIUMMultiple Cisco UCS-Based Products UEFI Secure Boot Bypass VulnerabilityEPSS 0.2%CVE-2025-43023MEDIUMHP Linux Imaging and Printing Software - Use of DSA KeyEPSS 0.2%