Falhas do tipo CWE-359

213 resultados

Violação de Privacidade

É quando um sistema expõe informações sensíveis de usuários (dados pessoais, credenciais, histórico de atividades) para quem não deveria ter acesso. Pode ocorrer por falha em controle de acesso, logs inadequados, cache inseguro ou falta de criptografia em trânsito/repouso.

Exemplo

Uma API REST que retorna email e CPF de outros usuários ao consultar um endpoint de perfil sem validar se o solicitante tem permissão; ou um sistema que registra senhas em log de erro visível aos administradores.

Como mitigar

Implemente controle de acesso rigoroso (verifique permissão antes de expor dados), evite armazenar dados sensíveis em logs/cache, criptografe dados em repouso e em trânsito (HTTPS, TLS), e aplique princípio de menor privilégio nas queries de banco de dados.

CVE-2026-26237MEDIUMQuMagieEPSS 0.3%CVE-2025-62362MEDIUMName and e-mail of employee that has done a publication is discoverable in gpp-burgerportaalEPSS 0.3%CVE-2025-49134LOWWeblate exposes personal IP address via e-mailEPSS 0.3%CVE-2025-0679MEDIUMExposure of Private Personal Information to an Unauthorized Actor in GitLabEPSS 0.3%CVE-2020-1688MEDIUMJunos OS: SRX and NFX Series: Insufficient Web API private key protectionEPSS 0.3%CVE-2024-13216MEDIUMHT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sensitive Information Exposure via HT Event: SponsorEPSS 0.3%CVE-2024-8891MEDIUMExposure of Private Personal Information to an Unauthorized Actor vulnerability on CIRCUTOR Q-SMTEPSS 0.3%CVE-2023-45720MEDIUMHCL Leap is affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2025-1030HIGHSensitive Data Exposure in Utarit Informatics' SoliClubEPSS 0.3%CVE-2026-84606HIGHA privacy issue was addressed with improved handling of identifiers. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, visiEPSS 0.3%CVE-2024-11216HIGHBroken Access Control in PozitifIK's Pik OnlineEPSS 0.3%CVE-2026-61588MEDIUMdjust's Django model serialization has no sensitive-field denylist: password hashes, privilege flags, and PII on a public view attribute are sent to the clientEPSS 0.3%CVE-2023-45721MEDIUMHCL Domino Volt and Domino Leap are affected by a disclosure of private personal information vulnerabilityEPSS 0.3%CVE-2024-42325LOWExcessive information returned by user.getEPSS 0.3%CVE-2026-53497MEDIUMCrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)EPSS 0.3%CVE-2025-14317HIGHUser Enumeration in Crazy Bubble Tea mobile applicationEPSS 0.3%CVE-2025-43259MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, mEPSS 0.3%CVE-2025-3035MEDIUMTab title disclosure across pages when using AI chatbotEPSS 0.3%CVE-2026-28938HIGHA privacy issue was addressed by moving sensitive data. This issue is fixed in iOS 26.6 and iPadOS 26.6. An app may be able to fingerprint tEPSS 0.3%CVE-2025-11959HIGHImproper Access Control in Premierturk's Excavation Management Information SystemEPSS 0.3%