Falhas do tipo CWE-538

93 resultados

Exposição de informações sensíveis em arquivos ou diretórios acessíveis externamente

A aplicação escreve dados sensíveis (senhas, tokens, chaves API, PII) em arquivos ou diretórios que podem ser acessados por usuários não autorizados ou pela internet. Isso acontece por falta de controle de permissões adequado ou armazenamento em local público, expondo credenciais e dados críticos.

Exemplo

Um aplicativo salva chaves de acesso ao banco de dados em um arquivo .config dentro da raiz web, ou gera logs de debug contendo tokens de autenticação em /tmp acessível globalmente. Um atacante consegue ler esses arquivos e comprometer a aplicação ou dados do usuário.

Como mitigar

Armazene dados sensíveis fora do escopo web (diretório não servido), use variáveis de ambiente ou sistemas de gestão de secrets (Vault, AWS Secrets Manager), aplique permissões restritivas (chmod 600) e evite logar ou cachear credenciais em texto plano.

CVE-2023-46723HIGHlte-pic32-writer's sendto.txt may disclose URL and the API keyEPSS 0.4%CVE-2026-7071MEDIUMCodeAstro Online Job Portal user-cvs file information disclosureEPSS 0.4%CVE-2025-31558MEDIUMWordPress TailPress plugin <= 0.4.4 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-27150MEDIUMTuleap dumps the Redis password into the generated troubleshooting archivesEPSS 0.4%CVE-2025-22306MEDIUMWordPress Link Whisper Free plugin <= 0.7.7 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2025-22773MEDIUMWordPress Htaccess File Editor <= 1.0.19 - Broken Authentication vulnerabilityEPSS 0.4%CVE-2026-46617HIGHFission runtime pods automount the fission-fetcher service-account token into the user function container, granting function code namespace-wide secret / configmap readEPSS 0.3%CVE-2025-22633MEDIUMWordPress Give – Divi Donation Modules plugin <= 2.0.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2026-10254MEDIUMSourceCodester Pet Grooming Management Software admin file information disclosureEPSS 0.3%CVE-2026-19229MEDIUMSourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosureEPSS 0.3%CVE-2025-12059CRITICALImproper Access Control in Logo Software's Logo j-PlatformEPSS 0.3%CVE-2022-23508HIGHGitOps Run allows for Kubernetes workload injectionEPSS 0.3%CVE-2025-24689MEDIUMWordPress Import and export users and customers plugin 1.27.12 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2023-54346HIGHWordPress Plugin Backup Migration 1.2.8 Unauthenticated Database Backup DownloadEPSS 0.3%CVE-2025-11891MEDIUMShelf Planner <= 2.8.1 - Unauthenticated Information Exposure via Log FilesEPSS 0.3%CVE-2025-58458MEDIUMIn Jenkins Git client Plugin 6.3.2 and earlier, except 6.1.4 and 6.2.1, Git URL field form validation responses differ based on whether the EPSS 0.3%CVE-2026-6160MEDIUMcode-projects Simple ChatBox Endpoint chatbox.sql SimpleChatbox_PHP file information disclosureEPSS 0.3%CVE-2025-31421MEDIUMWordPress Srbtranslatin plugin <= 3.2.0 - Sensitive Data Exposure vulnerabilityEPSS 0.3%CVE-2025-36372MEDIUMIBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tablesEPSS 0.3%CVE-2025-61138HIGHQlik Sense Enterprise v14.212.13 was discovered to contain an information leak via the /dev-hub/ directory.EPSS 0.3%