Falhas do tipo CWE-347

642 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2024-40592MEDIUMAn improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, verEPSS 0.1%CVE-2023-40727HIGHA vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application uses weak oEPSS 0.1%CVE-2025-43521MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2025-43390MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2026-1237LOWVulnerable cross-model authorization in juju. If a charm's cross-model permissions are revoked or expire, a malicious user who is able to upEPSS 0.1%CVE-2026-66776MEDIUMMultiple vulnerabilities in SAP Business AI Platform (Approuter)EPSS 0.1%CVE-2026-41005CRITICALUAA accepts SAML Encrypted Assertions authentication bypassEPSS 0.1%CVE-2026-57122HIGHPraisonAI: Webhook signature verification skipped (fail-open) when secret unset, allowing forged inbound webhooks (WhatsApp & Linear bots)EPSS 0.1%CVE-2026-95503MEDIUMKeycloak-services: keycloak-services: potential kdc spoofing bypass when kerberos password authentication is enabledEPSS 0.1%CVE-2026-34240HIGHjose vulnerable to untrusted JWK header key acceptance during signature verificationEPSS 0.1%CVE-2026-82645CRITICALAVideo Unauthenticated Stream Credential Disclosure via Forgeable TokenEPSS 0.1%CVE-2025-0824LOWlack of validation for firmware update in Hitachi Virtual StorageEPSS 0.1%CVE-2024-5912MEDIUMCortex XDR Agent: Improper File Signature Verification ChecksEPSS 0.1%CVE-2026-32294HIGHJetKVM insufficient firmware verificationEPSS 0.1%CVE-2026-48523MEDIUMPyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient` keysEPSS 0.1%CVE-2026-42193CRITICALPlunk: SNS webhook forgeryEPSS 0.1%CVE-2026-68745HIGHApache CloudStack: SAML2 Signature Validation Silently Skipped for Cert-less IdPEPSS 0.1%CVE-2024-23460MEDIUMIncorrect signature validation of packageEPSS 0.1%CVE-2024-47476HIGHDell NetWorker Management Console, version(s) 19.11, contain(s) an Improper Verification of Cryptographic Signature vulnerability. An unauthEPSS 0.1%CVE-2026-48021CRITICALepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vauEPSS 0.1%