Falhas do tipo CWE-668

236 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2022-46756HIGH Dell VxRail, versions prior to 7.0.410, contain a Container Escape Vulnerability. A local high-privileged attacker could potentially exploiEPSS 0.2%CVE-2026-82652MEDIUMSiYuan before v3.8.1 Information Disclosure via Publish AccessEPSS 0.2%CVE-2023-3670HIGHCodesys: Vulnerability in CODESYS Development System and CODESYS ScriptingEPSS 0.2%CVE-2026-34095NONEaction=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on ctype=text/javascript requestEPSS 0.2%CVE-2026-46430MEDIUMAlgernon: Auto-refresh SSE event server binds to all interfaces by default on Linux/macOSEPSS 0.2%CVE-2026-53657HIGHLima: An arbitrary user in a QEMU VM could gain the root privilege in the VM via the guest agent socketEPSS 0.2%CVE-2024-21813HIGHExposure of resource to wrong sphere in some Intel(R) DTT software installers may allow an authenticated user to potentially enable escalatiEPSS 0.2%CVE-2026-53826LOWOpenClaw < 2026.4.26 - Information Disclosure via Sandboxed Session SpawnEPSS 0.2%CVE-2023-24523HIGHAn attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7EPSS 0.2%CVE-2021-26343MEDIUMInsufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memoEPSS 0.2%CVE-2022-38087MEDIUMExposure of resource to wrong sphere in BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable informaEPSS 0.2%CVE-2026-72924LOWGitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by defaultEPSS 0.2%CVE-2021-41094MEDIUMMandatory encryption at rest can be bypassed (UI) in Wire appEPSS 0.2%CVE-2024-43704HIGHGPU DDK - PowerVR: PVRSRVAcquireProcessHandleBase can cause psProcessHandleBase reuse when PIDs are reusedEPSS 0.2%CVE-2022-26355Citrix Federated Authentication Service (FAS)EPSS 0.2%CVE-2023-5751HIGHCODESYS: Development system prone to DoS through exposure of resource to wrong sphereEPSS 0.2%CVE-2026-86551LOWWi-Fi MAC Address Obtainment by Non-privileged Program Vulnerability in ZTE Z80Ultra (NX741J) productEPSS 0.2%CVE-2026-34094LOWCustomized help link for page protection indicator is relative to subpage name, because the link target is missing the "/wiki/" prefixEPSS 0.2%CVE-2024-24985HIGHExposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalaEPSS 0.2%CVE-2025-15653HIGHDräger Zeus IE Anesthesia Workstation USB Interface Privilege EscalationEPSS 0.2%