Falhas do tipo CWE-347

641 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-20965HIGHWindows Admin Center Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2017-12333—A vulnerability in Cisco NX-OS System Software could allow an authenticated, local attacker to bypass signature verification when loading a EPSS 0.2%CVE-2026-2968MEDIUMCesanta Mongoose Poly1305 Authentication Tag tls_chacha20.c mg_chacha20_poly1305_decrypt signature verificationEPSS 0.2%CVE-2026-49454CRITICALRelyra SAML SignatureValue not cryptographically verified -> authentication bypassEPSS 0.2%CVE-2026-58085HIGHMissing MAC validation in wg(4) packet decryptionEPSS 0.2%CVE-2026-9832MEDIUMPayment Gateway of Stripe for WooCommerce <= 5.0.8 - Unauthenticated Improper Verification of Cryptographic Signature via woocommerce_api_wt_stripe Webhook EndpointEPSS 0.2%CVE-2023-54355HIGHPocketMine-MP 5.2.0 Server Crash via Incorrect EC CurveEPSS 0.2%CVE-2026-86304CRITICALMojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchorEPSS 0.2%CVE-2026-4600CRITICALVersions of the package jsrsasign before 11.1.1 are vulnerable to Improper Verification of Cryptographic Signature via the DSA domain-parameEPSS 0.2%CVE-2025-52550HIGHFirmware upgrade packages are unsignedEPSS 0.2%CVE-2026-76234HIGHlibcrux before 0.0.6 Cryptographic Implementation Bug FixesEPSS 0.2%CVE-2020-10608—In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI SyEPSS 0.2%CVE-2021-1453MEDIUMCisco IOS XE Software for the Catalyst 9000 Family Arbitrary Code Execution VulnerabilityEPSS 0.2%CVE-2026-85394CRITICALpython-jose through 3.5.0 Algorithm Confusion via DER-encoded Public Key as HMAC SecretEPSS 0.2%CVE-2026-42602HIGHazureauthextension Authenticate method does not validate bearer tokens, allowing auth bypass via replayEPSS 0.2%CVE-2026-46423CRITICALRocket.Chat: SAML signature validation skipped when IdP certificate field is emptyEPSS 0.2%CVE-2026-65616HIGHPotential privilege escalation to JFrog administrator privilegesEPSS 0.2%CVE-2026-35205HIGHHelm's plugin verification fails open when .prov is missing, allowing unsigned plugin installEPSS 0.2%CVE-2026-18108CRITICALNet::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypted content carries no signatureEPSS 0.2%CVE-2026-52767HIGHYesWiki: Unauthenticated ActivityPub Signature-Verification Bypass via `!openssl_verify(...)` accepting `int(-1)`EPSS 0.2%