Weaknesses of type CWE-538
86 resultsExposição de informações sensíveis em arquivos acessíveis externamente
A aplicação escreve dados sensíveis (credenciais, tokens, chaves) em arquivos ou diretórios que podem ser acessados por usuários não autorizados. Isso pode ocorrer em logs, caches, arquivos temporários ou diretórios web públicos, expondo informações críticas.
Example
Uma aplicação gera um relatório em PDF com dados de clientes e o salva na pasta /var/www/html (acessível pela web), ou registra tokens de autenticação em um arquivo de log legível por qualquer usuário do sistema.
How to mitigate
Restrinja permissões de arquivo (chmod 600 ou equivalente), nunca escreva dados sensíveis em diretórios públicos, use variáveis de ambiente ou gestores de secrets para credenciais, e implemente rotação/limpeza automática de logs que contenham informações confidenciais.
CVE-2026-50565MEDIUMFission builder pods auto-mount the fission-builder ServiceAccount token in the user-supplied builder containerEPSS 0.3%CVE-2022-4318HIGHCri-o: /etc/passwd tampering privescEPSS 0.2%CVE-2026-33705MEDIUMChamilo LMS has unauthenticated access to Twig template source files exposes application logicEPSS 0.2%CVE-2025-8452MEDIUMUnauthenticated leak of sensitive information affecting multiple models from Brother Industries, Ltd., Toshiba Tec, and Konica Minolta, Inc.EPSS 0.2%CVE-2025-68429HIGHStorybook manager bundle may expose environment variables during buildEPSS 0.2%CVE-2026-21672HIGHA vulnerability allowing local privilege escalation on Windows-based Veeam Backup & Replication servers.EPSS 0.2%CVE-2022-0013MEDIUMCortex XDR Agent: File Information Exposure Vulnerability When Generating Support FileEPSS 0.2%CVE-2026-5434MEDIUMImproper storage of sensitive informationEPSS 0.2%CVE-2024-31954HIGHAn issue was discovered in the installer in Samsung Portable SSD for T5 1.6.10 on Windows. Because it is possible to tamper with the directoEPSS 0.2%CVE-2025-36372MEDIUMIBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tablesEPSS 0.2%CVE-2019-25717MEDIUMDräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File DisclosureEPSS 0.2%CVE-2026-29114LOWA vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
EPSS 0.2%CVE-2025-46820HIGHphpgt/Dom exposes the GITHUB_TOKEN in Dom workflow run artifactEPSS 0.2%CVE-2025-12699MEDIUMZOLL ePCR IOS Mobile Application Insertion of Sensitive Information into Externally-Accessible File or DirectoryEPSS 0.2%CVE-2026-50099MEDIUMNaxclow IoT Platform Insertion of sensitive information into Externally-Accessible file or directoryEPSS 0.2%CVE-2023-38558MEDIUMA vulnerability has been identified in SIMATIC PCS neo (Administration Console) V4.0 (All versions), SIMATIC PCS neo (Administration ConsoleEPSS 0.2%CVE-2021-40363—A vulnerability has been identified in SIMATIC PCS 7 V8.2 (All versions), SIMATIC PCS 7 V9.0 (All versions), SIMATIC PCS 7 V9.1 (All versionEPSS 0.2%CVE-2026-27173HIGHApache Airflow CNCF Kubernetes provider: JWT Token Exposure in KubernetesExecutor Command-Line ArgumentsEPSS 0.2%CVE-2025-25586MEDIUMyimioa before v2024.07.04 was discovered to contain an information disclosure vulnerability via the component /resources/application.yml.EPSS 0.1%CVE-2023-5937MEDIUMSensitive data exfiltration via unsafe permissions on Windows systems in Arc before v1.6.0EPSS 0.1%