Falhas do tipo CWE-347

639 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2024-42004HIGHA library injection vulnerability exists in Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. A specially crafted library canEPSS 0.8%CVE-2020-15240HIGHRegression in JWT Signature ValidationEPSS 0.8%CVE-2024-41145HIGHA library injection vulnerability exists in the WebView.app helper app of Microsoft Teams (work or school) 24046.2813.2770.1094 for macOS. AEPSS 0.8%CVE-2026-3338HIGHPKCS7_verify Signature Validation Bypass in AWS-LCEPSS 0.8%CVE-2022-24771HIGHImproper Verification of Cryptographic Signature in node-forgeEPSS 0.8%CVE-2026-5588MEDIUMPKIX draft CompositeVerifier accepts empty signature sequence as valid.EPSS 0.8%CVE-2024-22461HIGHDell RecoverPoint for Virtual Machines 6.0.x contains an OS Command injection vulnerability. A low privileged remote attacker could potentiaEPSS 0.8%CVE-2021-29455HIGHMissing validation of JWT signature in `grassrootza/grassroot-platform`EPSS 0.8%CVE-2025-2233HIGHSamsung SmartThings Improper Verification of Cryptographic Signature Authentication Bypass VulnerabilityEPSS 0.8%CVE-2024-42220HIGHA library injection vulnerability exists in Microsoft Outlook 16.83.3 for macOS. A specially crafted library can leverage Outlook's access pEPSS 0.7%CVE-2024-41165HIGHA library injection vulnerability exists in Microsoft Word 16.83 for macOS. A specially crafted library can leverage Word's access privilegeEPSS 0.7%CVE-2024-43106HIGHA library injection vulnerability exists in Microsoft Excel 16.83 for macOS. A specially crafted library can leverage Excel's access privileEPSS 0.7%CVE-2017-15090An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signaturEPSS 0.7%CVE-2016-7064A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakageEPSS 0.7%CVE-2022-23610CRITICALImproper Verification of Cryptographic Signature in wire-serverEPSS 0.7%CVE-2026-12263HIGHAuthentication BypassEPSS 0.7%CVE-2026-9779HIGHATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution VulnerabilityEPSS 0.7%CVE-2021-3421A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seeminglyEPSS 0.7%CVE-2023-34058HIGHVMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges httpsEPSS 0.7%CVE-2023-28226MEDIUMWindows Enroll Engine Security Feature Bypass VulnerabilityEPSS 0.7%