Falhas do tipo CWE-93

207 resultados

Divulgação de informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) a usuários ou processos que não deveriam ter acesso. Isso acontece por falta de controle de acesso, logging inadequado, tratamento inseguro de erros ou armazenamento desprotegido. O risco é que um atacante obtém informações suficientes para escalar ataques, falsificar identidades ou comprometer outros sistemas.

Exemplo

Um serviço web retorna a senha do banco de dados em uma mensagem de erro quando a conexão falha; ou uma API expõe IDs internos de usuários em respostas públicas; ou logs de aplicação contêm chaves de API e são armazenados sem proteção de permissões.

Como mitigar

Implemente controle de acesso granular em dados sensíveis, sanitize mensagens de erro para nunca expor detalhes técnicos ao usuário final, criptografe dados em repouso e em trânsito, restrinja permissões de leitura em logs e arquivos de configuração, e faça code review focado em pontos de exposição de dados.

CVE-2018-12477LOWobs-service-refresh_patches can be tricked into deleting '..' or other unrelated directoriesEPSS 1.2%CVE-2023-26130HIGHVersions of the package yhirose/cpp-httplib before 0.12.4 are vulnerable to CRLF Injection when untrusted user input is used to set the contEPSS 1.1%CVE-2026-82854CRITICALNodemailer before 8.0.3 SMTP Command Injection via envelope.sizeEPSS 1.1%CVE-2023-23936MEDIUMCRLF Injection in Nodejs ‘undici’ via hostEPSS 1.1%CVE-2026-30227MEDIUMMimeKit: CRLF Injection in Quoted Local-Part Enables SMTP Command Injection and Email ForgeryEPSS 1.1%CVE-2026-42578LOWNetty: HTTP Header Injection via HttpProxyHandler Disabled ValidationEPSS 1.1%CVE-2023-38551HIGHA CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code onEPSS 1.0%CVE-2026-39849HIGHPi-hole FTL remote code execution via newline injection in dns.interface configurationEPSS 1.0%CVE-2023-49082MEDIUMaiohttp's ClientSession is vulnerable to CRLF injection via methodEPSS 0.9%CVE-2024-51981MEDIUMUnauthenticated Server Side Request Forgery (SSRF) via WS-Eventing affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, and Toshiba Tec, and Konica Minolta, Inc.EPSS 0.9%CVE-2026-57281HIGHJenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions mEPSS 0.9%CVE-2020-3246MEDIUMCisco Umbrella Carriage Return Line Feed Injection VulnerabilityEPSS 0.9%CVE-2020-15111MEDIUMCRLF vulnerability in FiberEPSS 0.9%CVE-2026-35517HIGHPi-hole FTL affected by Remote Code Execution (RCE) via dns.upstreams Newline InjectionEPSS 0.9%CVE-2021-4097MEDIUMCRLF Injection in phpservermon/phpservermonEPSS 0.8%CVE-2026-15429MEDIUMPrivilege Escalation via Improper Input Sanitization in TP-Link Archer VX1800vEPSS 0.8%CVE-2026-42258MEDIUMnet-imap: Command Injection via unvalidated Symbol inputsEPSS 0.8%CVE-2019-15616Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.EPSS 0.8%CVE-2025-27111MEDIUMEscape Sequence Injection vulnerability in Rack lead to Possible Log InjectionEPSS 0.7%CVE-2026-82853MEDIUMNodemailer before 8.0.5 SMTP Command Injection via CRLFEPSS 0.7%