Weaknesses of type CWE-538

88 results

Exposição de informações sensíveis em arquivos acessíveis externamente

A aplicação escreve dados sensíveis (credenciais, tokens, chaves) em arquivos ou diretórios que podem ser acessados por usuários não autorizados. Isso pode ocorrer em logs, caches, arquivos temporários ou diretórios web públicos, expondo informações críticas.

Example

Uma aplicação gera um relatório em PDF com dados de clientes e o salva na pasta /var/www/html (acessível pela web), ou registra tokens de autenticação em um arquivo de log legível por qualquer usuário do sistema.

How to mitigate

Restrinja permissões de arquivo (chmod 600 ou equivalente), nunca escreva dados sensíveis em diretórios públicos, use variáveis de ambiente ou gestores de secrets para credenciais, e implemente rotação/limpeza automática de logs que contenham informações confidenciais.

CVE-2019-15793MEDIUMMishandling of file-system uid/gid with namespaces in shiftfsEPSS 0.7%CVE-2024-22433HIGH Dell Data Protection Search 19.2.0 and above contain an exposed password opportunity in plain text when using LdapSettings.get_ldap_info inEPSS 0.6%CVE-2021-4471HIGHTG8 Firewall Unauthenticated User Password DisclosureEPSS 0.6%CVE-2016-15056HIGHUbee EVW3226 Unauthenticated Backup File DisclosureEPSS 0.6%CVE-2023-4480MEDIUMArbitrary File Read in Fusion File ManagerEPSS 0.6%CVE-2020-37104HIGHASTPP 4.0.1 VoIP Billing - Database Backup DownloadEPSS 0.6%CVE-2024-47579MEDIUMMultiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)EPSS 0.5%CVE-2019-25706HIGHAcross DR-810 ROM-0 Unauthenticated File DisclosureEPSS 0.5%CVE-2022-44623MEDIUMIn JetBrains TeamCity version before 2022.10, Project Viewer could see scrambled secure values in the MetaRunner settingsEPSS 0.5%CVE-2024-47580MEDIUMMultiple vulnerabilities in SAP NetWeaver AS for JAVA(Adobe Document Services)EPSS 0.5%CVE-2024-6880MEDIUMCSRF in MegaBIPEPSS 0.5%CVE-2026-49298HIGHApache Airflow: JWT Token Exposure in KubernetesExecutor Command-Line ArgumentsEPSS 0.5%CVE-2025-0194MEDIUMInsertion of Sensitive Information into Externally-Accessible File or Directory in GitLabEPSS 0.5%CVE-2022-26329LOWFile existence disclosue vulnerability in IDM pluginEPSS 0.5%CVE-2021-3709MEDIUMApport file permission bypass through emacs byte compilation errorsEPSS 0.5%CVE-2024-22045HIGHA vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information intoEPSS 0.4%CVE-2026-23838HIGHTandoor Recipes module allows SQLite database to be externally accessible with the default settingsEPSS 0.4%CVE-2023-46723HIGHlte-pic32-writer's sendto.txt may disclose URL and the API keyEPSS 0.4%CVE-2025-31550MEDIUMWordPress WP-LESS plugin <= 1.9.6 - Sensitive Data Exposure vulnerabilityEPSS 0.4%CVE-2026-7071MEDIUMCodeAstro Online Job Portal user-cvs file information disclosureEPSS 0.4%