Fallos del tipo CWE-668

217 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, dados pessoais, internals do sistema) através de canais ou comportamentos não pretendidos. O risco é que um atacante ou usuário não autorizado acesse informações que deveria estar protegidas, comprometendo confidencialidade.

Ejemplo

Uma API retorna stack traces completos em erros HTTP, revelando caminhos internos do servidor e bibliotecas usadas. Um atacante captura essa resposta e usa as informações para identificar versões vulneráveis e planejar exploits mais direcionados.

Cómo mitigar

Implemente tratamento de erros genérico (nunca exponha detalhes técnicos ao usuário final), use logging seguro para diagnóstico interno, aplique princípio do menor privilégio em acesso a dados, e realize auditorias regulares de o que sua aplicação expõe em respostas, logs e comentários de código.

CVE-2023-42792Apache Airflow: Improper access control to DAG resourcesEPSS 1.4%CVE-2022-35936HIGHEthermint DoS through Unintended Contract SelfdestructEPSS 1.4%CVE-2021-44523A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2021-44522A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2023-29355MEDIUMDHCP Server Service Information Disclosure VulnerabilityEPSS 1.3%CVE-2023-31103HIGHApache InLong: Attackers can change the immutable name and type of clusterEPSS 1.3%CVE-2023-34189Apache InLong: General user can delete and update processEPSS 1.3%CVE-2020-5386HIGHDell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list oEPSS 1.3%CVE-2023-31206HIGHApache InLong: Attackers can change the immutable name and type of nodesEPSS 1.2%CVE-2023-26081HIGHIn Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandEPSS 1.2%CVE-2022-45438MEDIUMApache Superset: Dashboard metadata information leakEPSS 1.2%CVE-2021-21878MEDIUMA local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0EPSS 1.2%CVE-2021-22869Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupEPSS 1.2%CVE-2021-23264HIGHTransmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter SearchEPSS 1.1%CVE-2022-22515HIGHA component of the CODESYS Control runtime system allows read and write access to configuration filesEPSS 1.1%CVE-2022-48198CRITICALThe ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code oEPSS 1.1%CVE-2023-39171HIGHSENEC Storage Box V1,V2 and V3 accidentially expose a management interfaceEPSS 1.1%CVE-2022-24074Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itEPSS 1.1%CVE-2021-39184MEDIUMSandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIEPSS 1.1%CVE-2022-24823MEDIUMLocal Information Disclosure Vulnerability in io.netty:netty-codec-httpEPSS 1.0%