Falhas do tipo CWE-347

642 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-74244MEDIUMQuay: stripe webhook accepts forged events without signature verification in quayEPSS 0.1%CVE-2025-34500HIGHShuffle Master Deck Mate 2 Insecure Update ChainEPSS 0.1%CVE-2020-36843MEDIUMThe implementation of EdDSA in EdDSA-Java (aka ed25519-java) through 0.3.0 exhibits signature malleability and does not satisfy the SUF-CMA EPSS 0.1%CVE-2026-81714CRITICALopenssl_encrypt before 1.4.9 Plugin Signing Trust Anchor Enrollment BypassEPSS 0.1%CVE-2022-41666HIGHA CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that allows adversaries with local user privileges to load EPSS 0.1%CVE-2022-28751HIGHLocal Privilege Escalation in Zoom Client for Meetings for MacOSEPSS 0.1%CVE-2026-25793HIGHNebula Has Possible Blocklist Bypass via ECDSA Signature MalleabilityEPSS 0.1%CVE-2023-41744HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Agent (macOS) befEPSS 0.1%CVE-2025-64186HIGHEvervault Go SDK: Incomplete PCR Validation in Enclave Attestation for non-Evervault hosted EnclavesEPSS 0.1%CVE-2026-20699MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2022-25333HIGHFlawed SK_LOAD module authenticity check in Texas Instruments OMAP L138EPSS 0.1%CVE-2026-86585HIGHImproper Verification of the Firmware Signature vulnerabilityEPSS 0.1%CVE-2026-22818HIGHJWT algorithm confusion in Hono JWK Auth Middleware when JWK lacks "alg" (untrusted header.alg fallback)EPSS 0.1%CVE-2026-75759HIGHEncrypted ID token or JARM response accepted without a nested signature in erlef oidccEPSS 0.1%CVE-2026-33467MEDIUMImproper Verification of Cryptographic Signature in Elastic Package Registry Leading to Package Integrity BypassEPSS 0.1%CVE-2022-1739MEDIUM2.2.1 IMPROPER VERIFICATION OF CRYPTOGRAPHIC SIGNATURE CWE-347EPSS 0.1%CVE-2026-40070HIGHbsv-sdk and bsv-wallet persist unverified certifier signatures in acquire_certificate (direct and issuance paths)EPSS 0.1%CVE-2022-2790MEDIUMEmerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature,EPSS 0.1%CVE-2023-34120HIGHImproper privilege management in Zoom for Windows, Zoom Rooms for Windows, and Zoom VDI for Windows clients before 5.14.0 may allow an authEPSS 0.1%CVE-2025-12007HIGHSupermicro BMC firmware update validation bypassEPSS 0.1%