Falhas do tipo CWE-347

639 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2022-39299HIGHSignature bypass via multiple root elements in Passport-SAMLEPSS 3.4%CVE-2020-24429HIGHAcrobat Reader DC for macOS Signature Verification Bypass Could Lead to Privilege EscalationEPSS 3.0%CVE-2025-31489HIGHMinIO performs incomplete signature validation for unsigned-trailer uploadsEPSS 2.4%CVE-2024-8698HIGHKeycloak-saml-core: improper verification of saml responses leading to privilege escalation in keycloakEPSS 2.0%CVE-2018-16151HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2018-16152HIGHIn verify_emsa_pkcs1_signature() in gmp_rsa_public_key.c in the gmp plugin in strongSwan 4.x and 5.x before 5.7.0, the RSA implementation baEPSS 1.9%CVE-2025-23369HIGHImproper Verification of Cryptographic Signature in GitHub Enterprise Server Allows Signature Spoofing by Improper ValidationEPSS 1.6%CVE-2019-14859HIGHA flaw was found in all python-ecdsa versions before 0.13.3, where it did not correctly verify whether signatures used DER encoding. WithoutEPSS 1.5%CVE-2024-6800CRITICALAn XML signature wrapping vulnerability was present in GitHub Enterprise Server (GHES) when using SAML authentication with specific identityEPSS 1.5%CVE-2026-47212MEDIUMSymfony: Twilio Notifier Webhook Parser Never Verifies the X-Twilio-Signature HMAC: Unauthenticated Webhook Event InjectionEPSS 1.5%CVE-2026-15013CRITICALSAML Single Sign On <= 5.4.3 - Unauthenticated Authentication Bypass via 'SAMLResponse' Parameter Signature Algorithm ConfusionEPSS 1.5%CVE-2021-41831Timestamp Manipulation with Signature WrappingEPSS 1.5%CVE-2024-0567HIGHGnutls: rejects certificate chain with distributed trustEPSS 1.4%CVE-2020-15705MEDIUMGRUB2: avoid loading unsigned kernels when GRUB is booted directly under secureboot without shimEPSS 1.4%CVE-2021-41830Double Certificate AttackEPSS 1.4%CVE-2020-15093HIGHImproper verification of signature threshold in toughEPSS 1.4%CVE-2021-41832Content Manipulation with Certificate Validation AttackEPSS 1.3%CVE-2023-5347CRITICALUnauthenticated Firmware UpgradeEPSS 1.3%CVE-2022-26510CRITICALA firmware update vulnerability exists in the iburn firmware checks functionality of InHand Networks InRouter302 V3.5.37. A specially-crafteEPSS 1.3%CVE-2021-21239MEDIUMOpen default xmlsec1 key-type preferenceEPSS 1.3%