Falhas do tipo CWE-93

167 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) a usuários ou processos que não deveriam ter acesso. Isso acontece por falta de controle de acesso, logging inadequado, tratamento inseguro de erros ou armazenamento desprotegido. O risco é que um atacante obtém informações suficientes para escalar ataques, falsificar identidades ou comprometer outros sistemas.

Exemplo

Um serviço web retorna a senha do banco de dados em uma mensagem de erro quando a conexão falha; ou uma API expõe IDs internos de usuários em respostas públicas; ou logs de aplicação contêm chaves de API e são armazenados sem proteção de permissões.

Como mitigar

Implemente controle de acesso granular em dados sensíveis, sanitize mensagens de erro para nunca expor detalhes técnicos ao usuário final, criptografe dados em repouso e em trânsito, restrinja permissões de leitura em logs e arquivos de configuração, e faça code review focado em pontos de exposição de dados.

CVE-2025-61884HIGHVulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: Runtime UI). Supported versions that are affected aEPSS 97.8%KEVCVE-2022-0666HIGHCRLF Injection leads to Stack Trace Exposure due to lack of filtering at https://demo.microweber.org/ in microweber/microweberEPSS 44.3%CVE-2016-3115MEDIUMMultiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to bypass intended sheEPSS 37.0%CVE-2024-20337HIGHA vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriEPSS 29.9%CVE-2021-39172HIGHNew line injection during configuration editionEPSS 29.2%CVE-2023-4767MEDIUMImproper Neutralization of CRLF Sequences in ManageEngine Desktop CentralEPSS 2.9%CVE-2023-4768MEDIUMImproper Neutralization of CRLF Sequences in ManageEngine Desktop CentralEPSS 2.9%CVE-2020-11078MEDIUMCRLF injection in httplib2EPSS 2.6%CVE-2018-12537In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and linEPSS 2.5%CVE-2022-31014MEDIUMSMTP Command Injection in iCalendar Attachments to emails via newlines in Nextcloud ServerEPSS 2.5%CVE-2021-31164Apache Unomi log injectionEPSS 2.3%CVE-2026-39983HIGHFTP Command Injection via CRLF in basic-ftpEPSS 2.2%CVE-2025-57804MEDIUMh2 allows HTTP Request Smuggling due to illegal characters in headersEPSS 1.7%CVE-2025-59419MEDIUMNetty netty-codec-smtp SMTP Command Injection Vulnerability Allowing Email ForgeryEPSS 1.6%CVE-2026-23829MEDIUMMailpit has SMTP Header Injection via Regex BypassEPSS 1.4%CVE-2022-31150MEDIUMCRLF injection in request headersEPSS 1.4%CVE-2020-3561MEDIUMCisco Adaptive Security Appliance Software and Firepower Threat Defense Software WebVPN CRLF Injection VulnerabilityEPSS 1.3%CVE-2022-35948MEDIUMCRLF Injection in Nodejs ‘undici’ via Content-TypeEPSS 1.2%CVE-2018-12477LOWobs-service-refresh_patches can be tricked into deleting '..' or other unrelated directoriesEPSS 1.2%CVE-2025-25184MEDIUMPossible Log Injection in Rack::CommonLoggerEPSS 1.1%