Fallos del tipo CWE-88

252 resultados

Divulgação de Informações

Fraqueza onde a aplicação expõe dados sensíveis — senhas, tokens, chaves criptográficas, dados pessoais — para atores não autorizados. Pode ocorrer por erro de configuração, logs inadequados, mensagens de erro verbosas, armazenamento inseguro ou falta de controle de acesso.

Ejemplo

Um serviço web retorna a senha do banco de dados em mensagens de erro quando a conexão falha, ou uma API deixa chaves de API visíveis em arquivos de configuração commitados no repositório público. Outro caso: logs de produção contendo tokens de autenticação que qualquer pessoa com acesso ao servidor consegue ler.

Cómo mitigar

Implemente controle de acesso baseado em roles, sanitize mensagens de erro para usuários finais (log detalhado apenas internamente), revise variáveis de ambiente e configurações, nunca commite segredos no repositório, e aplique mascaramento em logs (ex: exibir apenas últimos 4 dígitos de tokens). Use scanners de secrets no CI/CD.

CVE-2021-34718HIGHCisco IOS XR Software Arbitrary File Read and Write VulnerabilityEPSS 1.6%CVE-2021-41146HIGHArbitrary command execution on Windows in qutebrowserEPSS 1.4%CVE-2022-45062CRITICALIn Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.EPSS 1.4%CVE-2023-50232HIGHInductive Automation Ignition getParams Argument Injection Remote Code Execution VulnerabilityEPSS 1.4%CVE-2024-9131HIGHA user with administrator privileges can perform command injectionEPSS 1.4%CVE-2024-20287MEDIUMA vulnerability in the web-based management interface of the Cisco WAP371 Wireless-AC/N Dual Radio Access Point (AP) with Single Point SetupEPSS 1.4%CVE-2024-3817CRITICALHashiCorp go-getter Vulnerable to Argument Injection When Fetching Remote Default Git BranchesEPSS 1.3%CVE-2025-21613CRITICALgo-git has an Argument Injection via the URL fieldEPSS 1.3%CVE-2023-44452HIGHLinux Mint Xreader CBT File Parsing Argument Injection Remote Code Execution VulnerabilityEPSS 1.3%CVE-2022-31749MEDIUMAuthenticated arbitrary file read/write in WatchGuard Fireware OSEPSS 1.3%CVE-2023-49096HIGHArgument Injection in FFmpeg codec parameters in JellyfinEPSS 1.3%CVE-2021-1484MEDIUMCisco SD-WAN vManage Command Injection VulnerabilityEPSS 1.2%CVE-2023-6792MEDIUMPAN-OS: OS Command Injection Vulnerability in the XML APIEPSS 1.1%CVE-2026-40079HIGHCacti: Command Injection via escape_command() no-op in RRDtool executionEPSS 1.1%CVE-2022-23740HIGHImproper Neutralization of Argument Delimiters in a Command in GitHub Enterprise Server leading to Remote Code ExecutionEPSS 1.1%CVE-2022-29215HIGHArgument Injection in RegionProtectEPSS 1.1%CVE-2022-42968CRITICALGitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.EPSS 1.1%CVE-2024-3684HIGHImproper Privilege Management was identified in GitHub Enterprise Server that allowed privilege escalation in the Management ConsoleEPSS 1.1%CVE-2026-22738CRITICALSpEL Injection via Unescaped Filter Key in SimpleVectorStore Leads to Remote Code ExecutionEPSS 1.1%CVE-2024-23731CRITICALThe OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function arguEPSS 1.1%