Falhas do tipo CWE-359
213 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2026-41182MEDIUMLangSmith SDK: Streaming token events bypass output redactionEPSS 0.2%CVE-2025-43279MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Tahoe 26. An app may be ablEPSS 0.2%CVE-2026-58510MEDIUMGHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->privateEPSS 0.2%CVE-2026-8990MEDIUMAuthentication Bypass in KidsviewEPSS 0.2%CVE-2025-53374LOWDokploy Improperly Discloses User Information via user.one EndpointEPSS 0.2%CVE-2025-43310MEDIUMA configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7, macOS Sonoma 14.8, macOS Tahoe EPSS 0.2%CVE-2020-25900MEDIUMHelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, EPSS 0.2%CVE-2025-43217MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.6 and iPadOS 18.6, iPadOS 17.7.9. Privacy Indicators for mEPSS 0.2%CVE-2025-27080MEDIUMAuthenticated Sensitive Information Disclosure exposes Credentials in AOS-CX Command Line InterfaceEPSS 0.2%CVE-2025-43409MEDIUMA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Tahoe 26.1. An apEPSS 0.2%CVE-2024-41780MEDIUMIBM Jazz Foundation information disclosureEPSS 0.2%CVE-2026-28836MEDIUMA correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.8.8. An attacker with physical access may be EPSS 0.2%CVE-2025-1939LOWTapjacking in Android Custom Tabs using transition animationsEPSS 0.2%CVE-2025-43439MEDIUMA privacy issue was addressed by removing sensitive data. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1, visEPSS 0.2%CVE-2023-42830LOWA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and EPSS 0.2%CVE-2025-53950MEDIUMAn Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin fEPSS 0.2%CVE-2025-43389MEDIUMA privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, iOS 26.1 and iPadOS 26.1EPSS 0.2%CVE-2025-66605LOWA vulnerability has been found in FAST/TOOLS provided by Yokogawa Electric Corporation.
Since there are input
fields on this webpage withEPSS 0.2%CVE-2025-43469MEDIUMA permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOS TahoEPSS 0.2%CVE-2025-36131MEDIUMIBM Db2 information disclosureEPSS 0.2%