Falhas do tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2022-44310HIGHIn Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived sharEPSS 0.7%CVE-2024-35199HIGHTorchServe gRPC Port ExposureEPSS 0.6%CVE-2022-21947HIGHrancher desktop: Dashboard API is network accessibleEPSS 0.6%CVE-2025-54126MEDIUMWebAssembly Micro Runtime's `--addr-pool` option allows all IPv4 addresses when subnet mask is not specifiedEPSS 0.6%CVE-2023-22892HIGHThere exists an information disclosure vulnerability in SmartBear Zephyr Enterprise through 7.15.0 that could be exploited by unauthenticateEPSS 0.6%CVE-2023-22777MEDIUMAuthenticated Information Disclosure in ArubaOS Web-based Management InterfaceEPSS 0.6%CVE-2023-22775MEDIUMAuthenticated Sensitive Information Disclosure in ArubaOS Command Line InterfaceEPSS 0.6%CVE-2023-26588HIGHUse of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The aEPSS 0.6%CVE-2026-45411CRITICALvm2: Sandbox Breakout Using Async GeneratorEPSS 0.6%CVE-2024-5660CRITICALUse of Hardware Page Aggregation (HPA) and Stage-1 and/or Stage-2 translation on Cortex-A77, Cortex-A78, Cortex-A78C, Cortex-A78AE, Cortex-AEPSS 0.6%CVE-2023-26458MEDIUM Information Disclosure vulnerability in SAP Landscape ManagementEPSS 0.6%CVE-2026-39911HIGHHashgraph Guardian 3.5.1 Unsandboxed JavaScript Execution RCEEPSS 0.5%CVE-2022-3866MEDIUMNomad Workload Identity Token Can List Non-sensitive Metadata for Paths Under nomad/EPSS 0.5%CVE-2026-42535CRITICALApache HTTP Server: mod_dav_fs protected directory accessEPSS 0.5%CVE-2021-41088HIGHRemote code execution via the web UI backend of ElvishEPSS 0.5%CVE-2026-54582MEDIUMmport package installation can overwrite existing unmanaged or differently owned filesEPSS 0.5%CVE-2023-25192MEDIUMAMI MegaRAC SPX devices allow User Enumeration through Redfish. The fixed versions are SPx12-update-7.00 and SPx13-update-5.00.EPSS 0.5%CVE-2025-34064CRITICALOneLogin AD Connector Log S3 Bucket Hijack Leading to Cross-Tenant Data LeakageEPSS 0.5%CVE-2026-25725HIGHClaude Code Has Sandbox Escape via Persistent Configuration Injection in settings.jsonEPSS 0.5%CVE-2026-29093HIGHWWBN AVideo: Unauthenticated PHP session store exposed to host network via published memcached portEPSS 0.5%