Fallos del tipo CWE-213

32 resultados

Exposição de informações sensíveis por políticas incompatíveis

Ocorre quando políticas de segurança ou controle de acesso não estão alinhadas entre componentes, permitindo que dados sensíveis vazem através de caminhos que uma política permite mas outra deveria bloquear. O risco é que informações confidenciais (senhas, tokens, dados pessoais) ficam acessíveis porque as camadas de proteção trabalham em desacordo.

Ejemplo

Um sistema que bloqueia acesso direto a arquivos sensíveis via API, mas a política de cache HTTP permite que um proxy intermediário armazene e sirva esses dados publicamente. Ou um microsserviço que valida permissões na entrada, mas delega controle de acesso a um banco de dados com políticas de visibilidade diferentes, expondo registros que deveria esconder.

Cómo mitigar

Verifique que políticas de segurança estão sincronizadas em todas as camadas (aplicação, banco de dados, cache, proxy). Implemente um padrão único de autorização e revise explicitamente cada ponto onde dados sensíveis transitam — não confie que uma política em um lugar protege dados que passam por outro.

CVE-2019-10247In Eclipse Jetty version 7.x, 8.x, 9.2.27 and older, 9.3.26 and older, and 9.4.16 and older, the server running on any OS and Jetty version EPSS 5.8%CVE-2019-10246In Eclipse Jetty version 9.2.27, 9.3.26, and 9.4.16, the server running on Windows is vulnerable to exposure of the fully qualified Base ResEPSS 4.0%CVE-2019-1010283Univention Corporate Server univention-directory-notifier 12.0.1-3 and earlier is affected by: CWE-213: Intentional Information Exposure. ThEPSS 1.4%CVE-2025-54831MEDIUMApache Airflow: Connection sensitive details exposed to users with READ permissionsEPSS 0.9%CVE-2017-3211MEDIUMCentire Yopify leaks customer informationEPSS 0.8%CVE-2022-22541SAP BusinessObjects Business Intelligence Platform - versions 420, 430, may allow legitimate users to access information they shouldn't see EPSS 0.8%CVE-2020-1652MEDIUMJunos Space: OpenNMS is accessible via port 9443EPSS 0.7%CVE-2022-30350HIGHAvanquest Software RAD PDF (PDFEscape Online) 3.19.2.2 is vulnerable to Information Leak / Disclosure. The PDFEscape Online tool provides usEPSS 0.7%CVE-2024-7267HIGHInternal infrastructure data leak in EZD RPEPSS 0.6%CVE-2023-3441MEDIUMExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.6%CVE-2023-36919MEDIUMInformation Disclosure in SAP Enable NowEPSS 0.5%CVE-2023-6517HIGHSeeing the SMS Verification Code in Mia Technology's Mia-MedEPSS 0.5%CVE-2023-40570MEDIUMDatasette 1.0 alpha series leaks names of databases and tables to unauthenticated usersEPSS 0.5%CVE-2025-4976MEDIUMExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.4%CVE-2026-33216HIGHNATS has MQTT plaintext password disclosureEPSS 0.4%CVE-2024-49354MEDIUMIBM Concert information disclosureEPSS 0.3%CVE-2023-5117LOWExposure of Sensitive Information Due to Incompatible Policies in GitLabEPSS 0.3%CVE-2025-24316MEDIUMDario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible PoliciesEPSS 0.3%CVE-2024-44121MEDIUMInformation Disclosure in SAP S/4 HANA (Statutory Reports)EPSS 0.3%CVE-2023-27465MEDIUMA vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), EPSS 0.3%