Fallos del tipo CWE-88

252 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2022-28391HIGHBusyBox through 1.35.0 allows remote attackers to execute arbitrary code if netstat is used to print a DNS PTR record's value to a VT compatEPSS 3.5%CVE-2021-3540MEDIUMIvanti MobileIron Core clish Restricted Shell Escape via Argument InjectionEPSS 3.3%CVE-2021-43809MEDIUMLocal Code Execution through Argument Injection via dash leading git url parameter in GemfileEPSS 2.8%CVE-2023-47804Apache OpenOffice: Macro URL arbitrary script executionEPSS 2.7%CVE-2025-24293CRITICAL# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe imageEPSS 2.4%CVE-2022-31084CRITICALUnauthenticated Remote Code Execution in ldap-account-managerEPSS 2.4%CVE-2021-21386CRITICALImproper Neutralization of Argument Delimiters in a Decompiling Package ProcessEPSS 2.3%CVE-2023-25356HIGHCoreDial sipXcom up to and including 21.04 is vulnerable to Improper Neutralization of Argument Delimiters in a Command. XMPP users are ableEPSS 2.1%CVE-2026-35585HIGHFile Browser has a Command Injection via Hook RunnerEPSS 1.9%CVE-2024-39710CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a rEPSS 1.9%CVE-2023-6269CRITICALArgument injection vulnerability in Atos Unify OpenScape Session Border Controller, Atos Unify OpenScape Branch and Atos Unify OpenScape BCFEPSS 1.9%CVE-2024-58275HIGHEasywall 0.3.1 - Authentication Bypass via Command Injection in /ports-save EndpointEPSS 1.8%CVE-2026-40047CRITICALApache Camel: Camel-Docling: Insufficient validation of custom CLI arguments enables argument injection and path traversal in DoclingProducerEPSS 1.8%CVE-2024-39711CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a EPSS 1.7%CVE-2024-38656CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a rEPSS 1.7%CVE-2024-38655CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18EPSS 1.7%CVE-2024-39712CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a rEPSS 1.7%CVE-2024-11633CRITICALArgument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve EPSS 1.7%CVE-2021-24030The fbgames protocol handler registered as part of Facebook Gameroom does not properly quote arguments passed to the executable. That allowsEPSS 1.7%CVE-2017-1001003math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creatinEPSS 1.7%