Falhas do tipo CWE-347

642 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2026-48021CRITICALepa4all Security Incident: Implement keystore based on Telematik TSL, implement hostname check and certificate check for lib-vauEPSS 0.1%CVE-2024-38807MEDIUMCVE-2024-38807: Signature Forgery Vulnerability in Spring Boot's LoaderEPSS 0.1%CVE-2025-27498MEDIUMAEADs/ascon-aead: Plaintext exposed in decrypt_in_place_detached even on tag verification failureEPSS 0.1%CVE-2026-27445MEDIUMPGP Signature ReflectionEPSS 0.1%CVE-2025-34503HIGHShuffle Master Deck Mate 1 Unauthenticated EEPROM Firmware ExecutionEPSS 0.1%CVE-2022-4418HIGHLocal privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect HomEPSS 0.1%CVE-2026-13305MEDIUMAutel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution VulnerabilityEPSS 0.1%CVE-2023-32449HIGH Dell PowerStore versions prior to 3.5 contain an improper verification of cryptographic signature vulnerability. An attacker can trick a hiEPSS 0.1%CVE-2023-23431HIGH Some Honor products are affected by signature management vulnerability, successful exploitation could cause the forged system file overwritEPSS 0.1%CVE-2026-44309MEDIUMgitsign verify accepts signatures over go-git-normalized bytes, enabling trust confusion on malformed commitsEPSS 0.1%CVE-2026-45575HIGHepa4all-client: Improper Verification of Cryptographic SignatureEPSS 0.1%CVE-2024-27247MEDIUMZoom Desktop Client for macOS - Improper Privilege ManagementEPSS 0.1%CVE-2025-43468MEDIUMA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2026-58262HIGHKlever-Go: PubKeysBitmap padding bits bypass the BLS signature quorumEPSS 0.1%CVE-2025-2866LOWPDF signature forgery with adbe.pkcs7.sha1 SubFilterEPSS 0.1%CVE-2026-63237MEDIUMTOTP two-factor authentication bypass vulnerabilityEPSS 0.1%CVE-2025-52648MEDIUMHCL AION is affected by a vulnerability where offering images are not digitally signed. Lack of image signing may allow the use of unverifieEPSS 0.1%CVE-2024-1150HIGHImproper validation of update packagesEPSS 0.1%CVE-2025-43522LOWA downgrade issue affecting Intel-based Mac computers was addressed with additional code-signing restrictions. This issue is fixed in macOS EPSS 0.1%CVE-2025-32060MEDIUMAbsence of Kernel Module Signature Verification on Linux System of Infotainment ECUEPSS 0.1%