Fallos del tipo CWE-668

216 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (credenciais, chaves, dados pessoais, internals do sistema) através de canais ou comportamentos não pretendidos. O risco é que um atacante ou usuário não autorizado acesse informações que deveria estar protegidas, comprometendo confidencialidade.

Ejemplo

Uma API retorna stack traces completos em erros HTTP, revelando caminhos internos do servidor e bibliotecas usadas. Um atacante captura essa resposta e usa as informações para identificar versões vulneráveis e planejar exploits mais direcionados.

Cómo mitigar

Implemente tratamento de erros genérico (nunca exponha detalhes técnicos ao usuário final), use logging seguro para diagnóstico interno, aplique princípio do menor privilégio em acesso a dados, e realize auditorias regulares de o que sua aplicação expõe em respostas, logs e comentários de código.

CVE-2023-27976HIGH A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a maliEPSS 0.8%CVE-2021-30153MEDIUMAn issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisEPSS 0.8%CVE-2023-45911CRITICALAn issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.EPSS 0.8%CVE-2026-44009CRITICALvm2: Sandbox Breakout Through Null Proto ExceptionEPSS 0.8%CVE-2022-38599MEDIUMTeleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web iEPSS 0.8%CVE-2023-25409HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.EPSS 0.8%CVE-2022-39015Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.EPSS 0.8%CVE-2023-37911MEDIUMorg.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsEPSS 0.8%CVE-2022-45895MEDIUMPlanet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx inEPSS 0.7%CVE-2019-1848CRITICALCisco DNA Center Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-22281HIGHApache Helix Front (UI): Helix front hard-coded secret in the express-sessionEPSS 0.7%CVE-2020-12142MEDIUMIPSec UDP key material can be retrieved from EdgeConnect by a user with admin credentialsEPSS 0.7%CVE-2020-22647CRITICALAn issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.EPSS 0.7%CVE-2026-34538MEDIUMApache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)EPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2026-28779HIGHApache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsEPSS 0.7%CVE-2022-2882MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 beforeEPSS 0.7%CVE-2022-44310HIGHIn Development IL ecdh before 0.2.0, an attacker can send an invalid point (not on the curve) as the public key, and obtain the derived sharEPSS 0.7%CVE-2022-31596MEDIUMUnder certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjEPSS 0.7%CVE-2024-35199HIGHTorchServe gRPC Port ExposureEPSS 0.6%