Falhas do tipo CWE-668

235 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2020-26261HIGHuser-readable api tokens in systemd unitsEPSS 0.5%CVE-2025-23205MEDIUM`frame-ancestors: self` grants all users access to formgrader in nbgraderEPSS 0.5%CVE-2023-39040MEDIUMAn information leak in Cheese Cafe Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2026-14960CRITICALCVE-2026-14960EPSS 0.5%CVE-2023-39046MEDIUMAn information leak in TonTon-Tei_waiting Line v13.6.1 allows attackers to obtain the channel access token and send crafted messages.EPSS 0.5%CVE-2019-9011MEDIUMIn Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames.EPSS 0.4%CVE-2026-30912HIGHApache Airflow: Exposing stack trace in case of constraint errorEPSS 0.4%CVE-2022-41874LOWTauri Filesystem Scope can be Partially BypassedEPSS 0.4%CVE-2026-72764MEDIUMn8n before 1.123.67 Module Cache Poisoning via Code NodeEPSS 0.4%CVE-2026-56077HIGHPraisonAI - Information Disclosure via Shared MultiAgentLedger StateEPSS 0.4%CVE-2023-42716HIGHIn telephony service, there is a possible missing permission check. This could lead to remote information disclosure no additional executionEPSS 0.4%CVE-2023-45145LOWRedis Unix-domain socket may have be exposed with the wrong permissions for a short time window.EPSS 0.4%CVE-2022-32530MEDIUMA CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong seEPSS 0.4%CVE-2026-24473MEDIUMHono has an Arbitrary Key Read in Serve static Middleware (Cloudflare Workers Adapter)EPSS 0.4%CVE-2024-51754LOWUnguarded calls to __toString() when nesting an object into an array in TwigEPSS 0.4%CVE-2026-14611MEDIUMDeepMyst Mysti Per-Project Auto-Memory MemoryManager.ts initProjectMemory exposure of resourceEPSS 0.4%CVE-2024-51755LOWUnguarded calls to __isset() and to array-accesses when the sandbox is enabled in TwigEPSS 0.4%CVE-2026-32690LOWApache Airflow: 3.x - Nested Variable Secret Values Bypass Redaction via max_depth=1EPSS 0.4%CVE-2026-28806CRITICALImproper authorization in device bulk actions and device update API allows cross-organization device controlEPSS 0.4%CVE-2026-53648MEDIUMFOSSBilling: Downloadable product files can be overwritten through filename collisionsEPSS 0.4%