Falhas do tipo CWE-359

213 resultados

Violação de Privacidade

É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.

Exemplo

Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.

Como mitigar

Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.

CVE-2023-44255LOWAn exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 anEPSS 0.6%CVE-2025-43405HIGHA permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, maEPSS 0.6%CVE-2025-43399HIGHThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.7.2 and iPadOS 18.7.2, macOS SequoiEPSS 0.6%CVE-2024-46979MEDIUMData leak of notification filters of users in XWiki PlatformEPSS 0.5%CVE-2026-58296HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2026-58297HIGHMicrosoft Edge for Android Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-29888MEDIUMSaleor vulnerable to customers addresses leak when using Warehouse as a `Pickup: Local stock only` delivery methodEPSS 0.5%CVE-2025-66171MEDIUMApache CloudStack: Any user can create a new VM from backups they should not have access toEPSS 0.5%CVE-2021-36723MEDIUMEmuse - eServices / eNvoice Exposure Of Private Personal InformationEPSS 0.5%CVE-2023-50053HIGHAn issue in Foundation.app Foundation platform 1.0 allows a remote attacker to obtain sensitive information via the Web3 authentication procEPSS 0.5%CVE-2022-46168LOWGroup SMTP user emails are exposed in CC email headerEPSS 0.5%CVE-2024-13215MEDIUMElementor Addon Elements <= 1.13.10 - Authenticated (Contributor+) Sensitive Information Exposure via Modal PopupEPSS 0.5%CVE-2023-6695MEDIUMBeaver Themer <= 1.4.9 - Authenticated (Contributor+) Sensitive Information Exposure via shortcodeEPSS 0.5%CVE-2024-29986MEDIUMMicrosoft Edge for Android (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%CVE-2024-30321HIGHA vulnerability has been identified in SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC05), SIMATIC WinCC Runtime Professional V18 (All versioEPSS 0.5%CVE-2025-66172HIGHApache CloudStack: Any user can attach a volume in their VMs from backups they should not have access toEPSS 0.5%CVE-2023-2239HIGHExposure of Private Personal Information to an Unauthorized Actor in microweber/microweberEPSS 0.5%CVE-2022-2720MEDIUMIn affected versions of Octopus Server it was identified that when a sensitive value is a substring of another value, sensitive value maskinEPSS 0.5%CVE-2023-25819MEDIUMDiscourse tags with no visibility are leaking into og:article:tagEPSS 0.5%CVE-2024-49025MEDIUMMicrosoft Edge (Chromium-based) Information Disclosure VulnerabilityEPSS 0.5%