Weaknesses of type CWE-203

308 results

Discrepância observável em resposta de erro

A aplicação expõe informações diferentes em suas respostas de erro dependendo de condições internas (ex: usuário existe ou não, senha correta ou não, arquivo encontrado ou não), permitindo que um atacante deduza informações sensíveis através de análise de timing, mensagens ou códigos de status. O risco está em vazar informações que não deveriam ser públicas.

Example

Um endpoint de login retorna 'Usuário não encontrado' quando o email não existe, mas 'Senha incorreta' quando o email existe mas a senha está errada. Um atacante usa essas mensagens para enumerar emails válidos da plataforma sem precisar saber a senha de ninguém.

How to mitigate

Padronize todas as respostas de erro para o mesmo status HTTP e mensagem genérica (ex: sempre 'Credenciais inválidas'). Use timing constante nas verificações criptográficas e operações sensíveis para evitar ataques por timing side-channel.

CVE-2024-45231MEDIUMAn issue was discovered in Django v5.1.1, v5.0.9, and v4.2.16. The django.contrib.auth.forms.PasswordResetForm class, when used in a view imEPSS 0.8%CVE-2023-33741HIGHMacrovideo v380pro v1.4.97 shares the device id and password when sharing the device.EPSS 0.8%CVE-2023-25741MEDIUMWhen dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused EPSS 0.8%CVE-2023-51437HIGHApache Pulsar: Timing attack in SASL token signature verificationEPSS 0.8%CVE-2020-1685MEDIUMJunos OS: EX4600, QFX5K Series: Stateless firewall filter matching 'user-vlan-id' will cause incomplete discard actionEPSS 0.8%CVE-2024-48644MEDIUMAccounts enumeration vulnerability in the Login Component of Reolink Duo 2 WiFi Camera (Firmware Version v3.0.0.1889_23031701) allows remoteEPSS 0.8%CVE-2024-13028MEDIUMAntabot White-Jotter login observable response discrepancyEPSS 0.7%CVE-2023-29850HIGHSENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain inforEPSS 0.7%CVE-2024-5690MEDIUMBy monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's EPSS 0.7%CVE-2023-50708MEDIUMyii2-authclient vulnerable to possible timing attack on string comparison in OAuth1, OAuth2 and OpenID Connect implementationEPSS 0.7%CVE-2026-21484MEDIUMAnythingLLM Vulnerable to Username Enumeration w/ Password RecoveryEPSS 0.7%CVE-2021-4286LOWcocagne pysrp _ctsrp.py calculate_x information exposureEPSS 0.7%CVE-2023-34878HIGHAn issue was discovered in Ujcms v6.0.2 allows attackers to gain sensitive information via the dir parameter to /api/backend/core/web-file-hEPSS 0.7%CVE-2022-47952LOWlxc-user-nic in lxc through 5.0.1 is installed setuid root, and may allow local users to infer whether any file exists, even within a protecEPSS 0.7%CVE-2024-10463HIGHVideo frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, FirefEPSS 0.7%CVE-2022-45403MEDIUMService Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media cEPSS 0.7%CVE-2024-37880HIGHThe Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timEPSS 0.7%CVE-2024-13198MEDIUMlanghsu Mblog Blog System login observable response discrepancyEPSS 0.7%CVE-2022-43411MEDIUMJenkins GitLab Plugin 1.5.35 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhooEPSS 0.7%CVE-2022-45416MEDIUMKeyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as PriEPSS 0.7%