Fallos del tipo CWE-202

37 resultados

Exposição de informações sensíveis através de consultas de dados

Ocorre quando a aplicação retorna dados sensíveis (senhas, tokens, IDs internos) em respostas de consultas, logs ou mensagens de erro, sem validar ou filtrar o que é exposto. O desenvolvedor não distingue entre dados públicos e privados na resposta, permitindo que um atacante extraia informações confidenciais simplesmente consultando a API ou observando as mensagens.

Ejemplo

Uma API REST retorna o objeto completo do usuário em uma busca por email, incluindo hash de senha, ID interno do banco de dados e chave de API. Um atacante pode fazer requisições em massa para enumerar usuários e coletar credenciais expostas nas respostas.

Cómo mitigar

Implemente serialização seletiva (use DTOs ou anotações como @JsonIgnore) para retornar apenas campos públicos. Revise logs e mensagens de erro para remover dados sensíveis. Teste respostas de API regularmente com ferramentas de análise estática para detectar exposições antes da produção.

CVE-2026-42797MEDIUMApache Syncope: JexlContextBuilder Information DisclosureEPSS 0.4%CVE-2024-20388MEDIUMA vulnerability in the password change feature of Cisco Firepower Management Center (FMC) software could allow an unauthenticated, remote atEPSS 0.4%CVE-2021-1372MEDIUMCisco Webex Meetings Desktop App and Webex Productivity Tools for Windows Shared Memory Information Disclosure VulnerabilityEPSS 0.4%CVE-2024-38897MEDIUMWAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information.EPSS 0.4%CVE-2024-38892MEDIUMAn issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component.EPSS 0.4%CVE-2024-38895MEDIUMWAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information.EPSS 0.4%CVE-2026-25050LOWVendure vulnerable to timing attack that enables user enumeration in NativeAuthenticationStrategyEPSS 0.4%CVE-2025-29981HIGHDell Wyse Management Suite, versions prior to WMS 5.1, contains an Exposure of Sensitive Information Through Data Queries vulnerability. An EPSS 0.4%CVE-2024-2088HIGHNextScripts: Social Networks Auto-Poster <= 4.4.3 - Authenticated(Subscriber+) Sensitive Information ExposureEPSS 0.3%CVE-2025-64504MEDIUMLangfuse vulnerable to cross‑organization enumeration of member & invitation lists via project membership APIsEPSS 0.3%CVE-2025-36575HIGHDell Wyse Management Suite, versions prior to WMS 5.2, contain an Exposure of Sensitive Information Through Data Queries vulnerability. An uEPSS 0.3%CVE-2025-64528MEDIUMUsers are able to find users by name even when `enable_names` is offEPSS 0.3%CVE-2026-70473HIGHFlowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert historyEPSS 0.2%CVE-2021-4159A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be retEPSS 0.2%CVE-2026-3546MEDIUMe-shot <= 1.0.2 - Missing Authorization to Authenticated (Subscriber+) Sensitive Information Exposure via API Token via 'eshot_form_builder_get_account_data' AJAX ActionEPSS 0.2%CVE-2026-25703HIGHPotential information leakage from manager /network/graph API in NeuVectorEPSS 0.2%CVE-2026-33530HIGHInvenTree Vulnerable to ORM Filter InjectionEPSS 0.2%