Falhas do tipo CWE-497

402 resultados

Divulgação de Informações Sensíveis

Ocorre quando a aplicação expõe dados sensíveis (credenciais, tokens, caminhos internos, versões de software) através de mensagens de erro, logs, respostas HTTP, comentários no código ou outros canais acessíveis. O risco é que um atacante coleta essas informações para preparar ataques mais direcionados ou escalar privilégios.

Exemplo

Um erro de banco de dados não tratado exibe a query SQL completa e credenciais do BD ao usuário; ou um arquivo .git exposto no servidor revela histórico de commits com senhas hardcoded; ou stack traces detalhados em respostas de API revelam caminhos internos e bibliotecas desatualizadas.

Como mitigar

Implemente tratamento genérico de erros (nunca expor detalhes técnicos ao usuário final), configure logs seguros sem dados sensíveis, revise comentários e metadados antes de deploy, desabilite debug em produção, e escaneie repositórios antes de publicar (buscar secrets e arquivo .git).

CVE-2024-8687MEDIUMPAN-OS: Cleartext Exposure of GlobalProtect Portal PasscodesEPSS 0.4%CVE-2025-3606HIGHVestel AC Charger Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2025-54459HIGHVertikal Systems Hospital Manager Backend Services Exposure of Sensitive System Information to an Unauthorized Control SphereEPSS 0.4%CVE-2025-58579MEDIUMUsername Disclosure Through Missing AuthenticationEPSS 0.4%CVE-2025-1212MEDIUMExposure of Sensitive System Information to an Unauthorized Control Sphere in GitLabEPSS 0.4%CVE-2026-59528HIGHWordPress ShipTime: Discounted Shipping Rates plugin <= 1.1.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2024-31419MEDIUMCnv: information disclosure through the usage of vm-dump-metricsEPSS 0.4%CVE-2026-24222HIGHNVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper aEPSS 0.4%CVE-2025-47540MEDIUMWordPress weMail plugin <= 1.14.13 - Sensitive Data Exposure VulnerabilityEPSS 0.4%CVE-2026-81394MEDIUMMicrosoft Excel Information Disclosure VulnerabilityEPSS 0.4%CVE-2026-75928MEDIUMBrushfire unauthenticated information disclosureEPSS 0.4%CVE-2025-59098HIGHTrace Functionality Leaking Sensitive Data in dormakaba access managerEPSS 0.4%CVE-2024-10940MEDIUMExposure of Sensitive System Information via ImagePromptTemplate in langchain-ai/langchainEPSS 0.4%CVE-2025-14712HIGHJHENG GAO|Student Learning Assessment and Support System - Exposure of Sensitive InformationEPSS 0.4%CVE-2026-49068HIGHWordPress Coupon Affiliates plugin <= 7.8.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-42047HIGHInngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTTP methodsEPSS 0.4%CVE-2024-40706MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.4%CVE-2024-9470MEDIUMCortex XSOAR: Information Disclosure VulnerabilityEPSS 0.4%CVE-2025-26758MEDIUMWordPress Spotlight Social Feeds plugin <= 1.7.1 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-33141MEDIUMIBM QRadar SIEM could allow an authenticated user to obtain sensitive information from backup files due to incorrect permissions assignment.EPSS 0.4%