Falhas do tipo CWE-359
197 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2023-50719HIGHXWiki Platform Solr search discloses password hashes of all usersEPSS 83.5%CVE-2022-0482CRITICALExposure of Private Personal Information to an Unauthorized Actor in alextselegidis/easyappointmentsEPSS 38.7%CVE-2023-36052HIGHAzure CLI REST Command Information Disclosure VulnerabilityEPSS 21.5%CVE-2021-22876MEDIUMcurl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credenEPSS 5.3%CVE-2024-45591MEDIUMXWiki Platform document history including authors of any page exposed to unauthorized actorsEPSS 3.4%CVE-2022-24819MEDIUMUnauthenticated user can retrieve the list of users through uorgsuggest.vmEPSS 3.3%CVE-2026-28950MEDIUMA logging issue was addressed with improved data redaction. This issue is fixed in iOS 15.8.8 and iPadOS 15.8.8, iOS 16.7.16 and iPadOS 16.7EPSS 2.9%CVE-2022-0155HIGHExposure of Private Personal Information to an Unauthorized Actor in follow-redirects/follow-redirectsEPSS 2.4%CVE-2023-28303LOWWindows Snipping Tool Information Disclosure VulnerabilityEPSS 2.0%CVE-2024-11396MEDIUMEvent monster <= 1.4.3 - Information Exposure Via Visitors List ExportEPSS 2.0%CVE-2019-15623—Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Lookup ServerEPSS 1.9%CVE-2017-16769—Exposure of private information vulnerability in Photo Viewer in Synology Photo Station 6.8.1-3458 allows remote attackers to obtain metadatEPSS 1.9%CVE-2021-28559MEDIUMAdobe Acrobat Reader privacy violation vulnerability could lead to privilege escalationEPSS 1.6%CVE-2024-30056HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.6%CVE-2021-3980MEDIUMExposure of Private Personal Information to an Unauthorized Actor in elgg/elggEPSS 1.5%CVE-2023-36018HIGHVisual Studio Code Jupyter Extension Spoofing VulnerabilityEPSS 1.5%CVE-2024-26192HIGHMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.5%CVE-2025-54125HIGHXWiki Platform: Password and email exposure in xml.vm fieldsEPSS 1.3%CVE-2024-29987MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 1.2%CVE-2025-43227HIGHThis issue was addressed through improved state management. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6EPSS 1.2%