Falhas do tipo CWE-359

213 resultados

Violação de Privacidade

É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.

Exemplo

Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.

Como mitigar

Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.

CVE-2022-41936MEDIUMExposure of Private Personal Information to an Unauthorized Actor in xwiki-platform-rest-serverEPSS 0.8%CVE-2023-22918MEDIUMA post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEEPSS 0.8%CVE-2026-20834MEDIUMWindows Spoofing VulnerabilityEPSS 0.8%CVE-2023-35151HIGHXWiki Platform may show email addresses in clear in REST resultsEPSS 0.7%CVE-2023-29203LOWUnauthenticated user can have information about hidden users on subwikis through uorgsuggest.vm EPSS 0.7%CVE-2026-56171HIGHWindows Remote Desktop Protocol (RDP) Information Disclosure VulnerabilityEPSS 0.7%CVE-2025-66035HIGHAngular HTTP Client Has XSRF Token Leakage via Protocol-Relative URLsEPSS 0.7%CVE-2024-27850MEDIUMThis issue was addressed with improvements to the noise injection algorithm. This issue is fixed in Safari 17.5, iOS 17.5 and iPadOS 17.5, mEPSS 0.7%CVE-2023-7014MEDIUMAuthor Box, Guest Author and Co-Authors for Your Posts – Molongui <= 4.7.4 - Information Exposure via ma_debugEPSS 0.7%CVE-2026-56124HIGHphpUploader < 2.0.2 Unauthenticated Database Exposure via index modelEPSS 0.6%CVE-2019-25762HIGHJoomla! Component JoomProject 1.1.3.2 Information DisclosureEPSS 0.6%CVE-2026-24735HIGHApache Answer: Revision API Improper Access Control leads to Information DisclosureEPSS 0.6%CVE-2023-5983HIGHInformation Disclosure in Botanik Software Pharmacy AutomationEPSS 0.6%CVE-2026-62328HIGH9Router 0.4.41 - Unauthenticated Information Disclosure via API Usage EndpointsEPSS 0.6%CVE-2024-7697HIGHLogical vulnerability in com.transsion.carlcareEPSS 0.6%CVE-2024-10267HIGHInformation Disclosure in transformeroptimus/superagiEPSS 0.6%CVE-2020-37173HIGHAVideo Platform 8.1 - Information Disclosure (User Enumeration)EPSS 0.6%CVE-2023-1936LOWExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.6%CVE-2025-5334HIGHExposure of private personal information to an unauthorized actor in the user vaults component of Devolutions Remote Desktop Manager allows EPSS 0.6%CVE-2023-2703HIGHInformation Disclosure in Finex Media's Competition Management SystemEPSS 0.6%