Falhas do tipo CWE-538

93 resultados

Exposição de informações sensíveis em arquivos ou diretórios acessíveis externamente

A aplicação escreve dados sensíveis (senhas, tokens, chaves API, PII) em arquivos ou diretórios que podem ser acessados por usuários não autorizados ou pela internet. Isso acontece por falta de controle de permissões adequado ou armazenamento em local público, expondo credenciais e dados críticos.

Exemplo

Um aplicativo salva chaves de acesso ao banco de dados em um arquivo .config dentro da raiz web, ou gera logs de debug contendo tokens de autenticação em /tmp acessível globalmente. Um atacante consegue ler esses arquivos e comprometer a aplicação ou dados do usuário.

Como mitigar

Armazene dados sensíveis fora do escopo web (diretório não servido), use variáveis de ambiente ou sistemas de gestão de secrets (Vault, AWS Secrets Manager), aplique permissões restritivas (chmod 600) e evite logar ou cachear credenciais em texto plano.

CVE-2022-4318HIGHCri-o: /etc/passwd tampering privescEPSS 0.3%CVE-2022-20864MEDIUMCisco IOS XE ROM Monitor Software for Catalyst Switches Information Disclosure VulnerabilityEPSS 0.3%CVE-2018-4847A vulnerability has been identified in SIMATIC WinCC OA Operator iOS App (All versions < V1.4). Insufficient protection of sensitive informaEPSS 0.3%CVE-2022-43933MEDIUMconfiguration secrets are logged in support-saveEPSS 0.3%CVE-2025-68429HIGHStorybook manager bundle may expose environment variables during buildEPSS 0.3%CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2026-33705MEDIUMChamilo LMS has unauthenticated access to Twig template source files exposes application logicEPSS 0.2%CVE-2025-8452MEDIUMUnauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., Toshiba Tec, and Konica Minolta, Inc.EPSS 0.2%CVE-2026-12762MEDIUMInsertion of Sensitive Information into Externally-Accessible File in IBM Business Automation InsightsEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2022-0013MEDIUMCortex XDR Agent: File Information Exposure Vulnerability When Generating Support FileEPSS 0.2%CVE-2026-5434MEDIUMImproper storage of sensitive informationEPSS 0.2%CVE-2024-31954HIGHAn issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directoEPSS 0.2%CVE-2019-25717MEDIUMDräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File DisclosureEPSS 0.2%CVE-2026-29114LOWA vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that CA is installed and EPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2025-12699MEDIUMZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or DirectoryEPSS 0.2%CVE-2023-38558MEDIUMA vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration ConsoleEPSS 0.2%CVE-2026-50099MEDIUMNaxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directoryEPSS 0.2%CVE-2026-57442MEDIUMMCPVault: PathFilter restricted directories (.git/.obsidian/node_modules) only denied at vault root, not nestedEPSS 0.2%