Falhas do tipo CWE-347

640 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (credenciais, tokens, informações pessoais, detalhes técnicos) a atores não autorizados através de canais inseguros, logs, mensagens de erro ou respostas HTTP. O risco está em que essas informações podem ser capturadas, armazenadas ou usadas para ataques subsequentes.

Exemplo

Uma API retorna stacktrace completo (com caminhos internos e bibliotecas) em resposta de erro; ou um formulário envia senha em texto plano via HTTP; ou logs de produção contêm tokens de autenticação visíveis em backup público no GitHub.

Como mitigar

Sanitize mensagens de erro para o usuário (log completo apenas internamente), use HTTPS/TLS obrigatório para dados sensíveis, implemente rotação de secrets e nunca exponha tokens/senhas em logs, respostas ou comentários de código. Revise regularmente o que é exposto em respostas da aplicação e em pontos de debug.

CVE-2023-24025HIGHCRYSTALS-DILITHIUM (in Post-Quantum Cryptography Selected Algorithms 2022) in PQClean d03da30 may allow universal forgeries of digital signaEPSS 0.5%CVE-2021-20319An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the iEPSS 0.5%CVE-2023-42806MEDIUMSnapshot signature not including HeadID will allow replay attacksEPSS 0.5%CVE-2023-1204MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 10.1 before 15.10.8, all versions starting from 15.11 befoEPSS 0.5%CVE-2020-12042Opto 22 SoftPAC Project Version 9.6 and prior. Paths specified within the zip files used to update the SoftPAC firmware are not sanitized. AEPSS 0.5%CVE-2023-46234MEDIUMbrowserify-sign vulnerable via an upper bound check issue in `dsaVerify` that leads to a signature forgery attackEPSS 0.5%CVE-2024-13172HIGHImproper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows EPSS 0.5%CVE-2022-24759HIGHFailure to validate signature during handshake in @chainsafe/libp2p-noiseEPSS 0.5%CVE-2026-56451CRITICALA vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly validate the algorithm speciEPSS 0.5%CVE-2024-48949CRITICALThe verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) ||EPSS 0.5%CVE-2023-50714MEDIUMThe Oauth2 PKCE implementation is vulnerableEPSS 0.5%CVE-2026-50010HIGHNetty's wrapping plain trust manager silently disables hostname verificationEPSS 0.5%CVE-2023-40178MEDIUM@node-saml/node-saml's validatePostRequestAsync does not include checkTimestampsValidityErrorEPSS 0.5%CVE-2020-10759A PGP signature bypass flaw was found in fwupd (all versions), which could lead to the installation of unsigned firmware. As per upstream, aEPSS 0.5%CVE-2018-25099CRITICALIn the CryptX module before 0.062 for Perl, gcm_decrypt_verify() and chacha20poly1305_decrypt_verify() do not verify the tag.EPSS 0.5%CVE-2023-20266MEDIUMA vulnerability in Cisco Emergency Responder, Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager SessioEPSS 0.5%CVE-2026-23687HIGHXML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP PlatformEPSS 0.5%CVE-2025-55229MEDIUMWindows Certificate Spoofing VulnerabilityEPSS 0.5%CVE-2026-33117CRITICALAzure SDK for Java Security Feature Bypass VulnerabilityEPSS 0.5%CVE-2020-25166HIGHB. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplusEPSS 0.5%