Weaknesses of type CWE-347

534 results

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, PII, tokens) através de canais não seguros, logs, mensagens de erro ou comportamentos observáveis. O risco é um atacante capturar essas informações e usá-las para escalar privilégios, contornar autenticação ou comprometer outros sistemas.

Example

Uma API retorna stack traces detalhados em respostas de erro que revelam caminhos de arquivo, versões de bibliotecas e nomes de banco de dados; ou credenciais de acesso aparecem em logs de aplicação armazenados sem criptografia em um servidor comprometido.

How to mitigate

Remova informações técnicas sensíveis de mensagens de erro (envie logs detalhados apenas para backend seguro), criptografe dados em trânsito e em repouso, implemente controle de acesso a logs e trace requests com IDs genéricos. Use ferramentas de scanning estático para detectar exposição de hardcoded secrets.

CVE-2025-25292CRITICALRuby SAML vulnerable to SAML authentication bypass due to namespace handling (parser differential)EPSS 64.8%CVE-2025-59718CRITICALA improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiEPSS 63.4%KEVCVE-2013-3900MEDIUMWinVerifyTrust Signature Validation VulnerabilityEPSS 44.6%KEVCVE-2018-0114A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker to re-sign tokens uEPSS 42.7%CVE-2020-1464HIGHWindows Spoofing VulnerabilityEPSS 41.1%KEVCVE-2024-9487CRITICALAn Improper Verification of Cryptographic Signature vulnerability was identified in GitHub Enterprise Server that allowed SAML SSO authentication to be bypassed when the encrypted assertions feature was enabledEPSS 25.1%CVE-2025-59719CRITICALAn improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 tEPSS 25.0%CVE-2025-25291CRITICALruby-saml vulnerable to SAML authentication bypass due to DOCTYPE handling (parser differential)EPSS 20.3%CVE-2024-45607MEDIUMwhatsapp-api-js fails to validate message's signatureEPSS 14.5%CVE-2026-48558CRITICALSimpleHelp Authentication Bypass via Missing OIDC JWT Signature VerificationEPSS 11.5%CVE-2026-40372CRITICALASP.NET Core Elevation of Privilege VulnerabilityEPSS 11.2%CVE-2024-45409CRITICALThe Ruby SAML library vulnerable to a SAML authentication bypass via Incorrect XPath selectorEPSS 10.7%CVE-2025-29775CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via DigestValue CommentEPSS 9.4%CVE-2025-29774CRITICALxml-crypto Vulnerable to XML Signature Verification Bypass via Multiple SignedInfo ReferencesEPSS 9.0%CVE-2025-59934CRITICALFormbricks missing JWT signature verificationEPSS 8.0%CVE-2020-9047MEDIUMexacqVision Software - Improper Verification of Cryptographic SignatureEPSS 7.8%CVE-2026-29000CRITICALpac4j-jwt JwtAuthenticator Authentication BypassEPSS 5.9%CVE-2020-2021CRITICALPAN-OS: Authentication Bypass in SAML AuthenticationEPSS 4.4%KEVCVE-2025-47827MEDIUMIn IGEL OS before 11, Secure Boot can be bypassed because the igel-flash-driver module improperly verifies a cryptographic signature. UltimaEPSS 4.0%KEVCVE-2026-10795HIGHUpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypass via UpdraftCentral udrpcEPSS 3.6%