Falhas do tipo CWE-359
213 resultadosViolação de Privacidade
É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.
Exemplo
Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.
Como mitigar
Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.
CVE-2024-23211LOWA privacy issue was addressed with improved handling of user preferences. This issue is fixed in Safari 17.3, iOS 16.7.5 and iPadOS 16.7.5, EPSS 0.4%CVE-2024-36677HIGHIn the module "Login as customer PRO" (loginascustomerpro) <1.2.7 from Weblir for PrestaShop, a guest can access direct link to connect to eEPSS 0.4%CVE-2024-36682HIGHIn the module "Theme settings" (pk_themesettings) <= 1.8.8 from Promokit.eu for PrestaShop, a guest can download all email collected while SEPSS 0.4%CVE-2026-76855HIGHNetcore NR255-V 1.5.130703 Cross-User Session Disclosure via Audit EndpointsEPSS 0.4%CVE-2022-0852—There is a flaw in convert2rhel. convert2rhel passes the Red Hat account password to subscription-manager via the command line, which could EPSS 0.4%CVE-2025-41685MEDIUMSMA: Sunny Portal limited disclosure of personal data of registered users to an authenticated userEPSS 0.4%CVE-2026-92565MEDIUMRallly before 4.15.0 Information Disclosure via polls.getEPSS 0.4%CVE-2026-48048HIGHXWiki Platform's Livetable results still allow reconstructing password hashes using 768 requestsEPSS 0.4%CVE-2024-13228MEDIUMQubely – Advanced Gutenberg Blocks <= 1.8.13 - Authenticated (Contributor+) Sensitive Information Exposure via qubely_get_contentEPSS 0.4%CVE-2024-49765MEDIUMBypass of Discourse Connect using other login paths if enabled in DiscourseEPSS 0.4%CVE-2025-66510MEDIUMNextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact listEPSS 0.4%CVE-2025-68945MEDIUMIn Gitea before 1.21.2, an anonymous user can visit a private user's project.EPSS 0.4%CVE-2025-66027HIGHRallly Information Disclosure Vulnerability in Participant API Leaks Names and Emails Despite Pro Privacy SettingsEPSS 0.4%CVE-2024-13953MEDIUMSensitive Information disclosed in log filesEPSS 0.4%CVE-2023-6630MEDIUMContact Form 7 – Dynamic Text Extension <= 4.1.0 - Insecure Direct Object ReferenceEPSS 0.3%CVE-2026-7382MEDIUMInformation Disclosure in MeWare Software's PDKSEPSS 0.3%CVE-2025-26816MEDIUMA vulnerability in Intrexx Portal Server 12.0.2 and earlier which was classified as problematic potentially allows users with particular perEPSS 0.3%CVE-2025-25042MEDIUMAuthenticated Access Control Vulnerability allows Sensitive Information Disclosure in AOS-CX REST InterfaceEPSS 0.3%CVE-2026-3911LOWOrg.keycloak.services.resources.admin.userresource: keycloak: information disclosure of disabled user attributes via administrative endpointEPSS 0.3%CVE-2025-11145HIGHUser Enumeration in CBK Soft's enVisionEPSS 0.3%