Fallos del tipo CWE-668

219 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, dados pessoais, internals do sistema) através de canais ou comportamentos não pretendidos. O risco é que um atacante ou usuário não autorizado acesse informações que deveria estar protegidas, comprometendo confidencialidade.

Ejemplo

Uma API retorna stack traces completos em erros HTTP, revelando caminhos internos do servidor e bibliotecas usadas. Um atacante captura essa resposta e usa as informações para identificar versões vulneráveis e planejar exploits mais direcionados.

Cómo mitigar

Implemente tratamento de erros genérico (nunca exponha detalhes técnicos ao usuário final), use logging seguro para diagnóstico interno, aplique princípio do menor privilégio em acesso a dados, e realize auditorias regulares de o que sua aplicação expõe em respostas, logs e comentários de código.

CVE-2024-3019HIGHPcp: exposure of the redis server backend allows remote command execution via pmproxyEPSS 1.0%CVE-2022-0815MEDIUMMcAfee WebAdvisor - Extension Fingerprinting vulnerabilityEPSS 1.0%CVE-2022-29247LOWExposure of Resource to Wrong Sphere in ElectronEPSS 1.0%CVE-2023-34114HIGHExposure of resource to wrong sphere in Zoom for Windows and Zoom for MacOS clients before 5.14.10 may allow an authenticated user to potenEPSS 1.0%CVE-2023-28433HIGHMinio Privilege Escalation on Windows via Path separator manipulationEPSS 1.0%CVE-2021-40496SAP Internet Communication framework (ICM) - versions 700, 701, 702, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, 785, allows an attackEPSS 0.9%CVE-2021-20999CRITICALWEIDMUELLER: Accidentally open network port in u-controls and IoT-GatewaysEPSS 0.9%CVE-2022-1467HIGHAVEVA InTouch Access Anywhere Exposure of Resource to Wrong SphereEPSS 0.9%CVE-2023-35696HIGHUnauthenticated endpoints in the SICK ICR890-4 could allow an unauthenticated remote attacker to retrieve sensitive information about the deEPSS 0.9%CVE-2022-21718LOWRenderers can obtain access to random bluetooth device without permission in ElectronEPSS 0.9%CVE-2023-29208HIGHData leak through deleted documents EPSS 0.9%CVE-2026-20160CRITICALCisco Smart Software Manager On-Prem Arbitrary Command Execution VulnerabilityEPSS 0.9%CVE-2021-41140MEDIUMReactions leak for secure category topics and private messagesEPSS 0.9%CVE-2025-32428CRITICALJupyter Remote Desktop Proxy makes TigerVNC accessible via the network and not just via a UNIX socket as intendedEPSS 0.9%CVE-2020-26084MEDIUMCisco Edge Fog Fabric Resource Exposure VulnerabilityEPSS 0.9%CVE-2021-32788MEDIUMPost creator of a whisper post can be revealed to non-staff users in DiscourseEPSS 0.9%CVE-2022-20917MEDIUMA vulnerability in the Extensible Messaging and Presence Protocol (XMPP) message processing feature of Cisco Jabber could allow an authenticEPSS 0.9%CVE-2022-32249Under special integration scenario of SAP Business one and SAP HANA - version 10.0, an attacker can exploit HANA cockpit�s data volume to gaEPSS 0.9%CVE-2026-44008CRITICALvm2: Snabox breakout via `neutralizeArraySpeciesBatch`EPSS 0.9%CVE-2020-26086MEDIUMCisco TelePresence Collaboration Endpoint Software Information Disclosure VulnerabilityEPSS 0.8%