Falhas do tipo CWE-347

639 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2021-29451CRITICALMissing validation of JWT signature in `ManyDesigns/Portofino`EPSS 0.9%CVE-2022-24773MEDIUMImproper Verification of Cryptographic Signature in `node-forge`EPSS 0.9%CVE-2022-21134HIGHA firmware update vulnerability exists in the "update" firmware checks functionality of reolink RLC-410W v3.0.0.136_20121102. A spEPSS 0.9%CVE-2020-15091MEDIUMDenial of Service in TenderMintEPSS 0.9%CVE-2017-13083MEDIUMAkeo Consulting Rufus prior to version 2.17.1187 does not adequately validate the integrity of updates downloaded over HTTP, allowing an attEPSS 0.9%CVE-2024-41138HIGHA library injection vulnerability exists in the com.microsoft.teams2.modulehost.app helper app of Microsoft Teams (work or school) 24046.281EPSS 0.9%CVE-2020-15216MEDIUMSignature Validation Bypass in goxmldsigEPSS 0.9%CVE-2022-42010MEDIUMAn issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can caEPSS 0.9%CVE-2025-24043HIGHWinDbg Remote Code Execution VulnerabilityEPSS 0.9%CVE-2024-39804HIGHA library injection vulnerability exists in Microsoft PowerPoint 16.83 for macOS. A specially crafted library can leverage PowerPoint's acceEPSS 0.9%CVE-2026-54733CRITICALmoodle-local_o365: Authentication bypass via unverified JWT signature in Teams SSO endpointEPSS 0.9%CVE-2024-21917CRITICALRockwell Automation FactoryTalk® Service Platform Service Token VulnerabilityEPSS 0.9%CVE-2020-14515CodeMeter (All versions prior to 6.90 when using CmActLicense update files with CmActLicense Firm Code) has an issue in the license-file sigEPSS 0.8%CVE-2024-41159HIGHA library injection vulnerability exists in Microsoft OneNote 16.83 for macOS. A specially crafted library can leverage OneNote's access priEPSS 0.8%CVE-2024-32962CRITICALXML signature verification bypass due improper verification of signature / signature spoofingEPSS 0.8%CVE-2020-26244MEDIUMCryptographic issues in Python oicEPSS 0.8%CVE-2018-16557HIGHA vulnerability has been identified in SIMATIC S7-400 CPU 412-1 DP V7 (All versions), SIMATIC S7-400 CPU 412-2 DP V7 (All versions), SIMAEPSS 0.8%CVE-2021-29108HIGHThere is an privilege escalation vulnerability in organization-specific logins in Esri Portal for ArcGIS versions 10.9 and below.EPSS 0.8%CVE-2021-36226CRITICALWestern Digital My Cloud devices before OS5 do not use cryptographically signed Firmware upgrade files.EPSS 0.8%CVE-2023-35373MEDIUMMono Authenticode Validation Spoofing VulnerabilityEPSS 0.8%