Falhas do tipo CWE-212

68 resultados

Divulgação não intencional de informações sensíveis

A aplicação expõe dados confidenciais (senhas, tokens, chaves, dados pessoais) através de canais ou contextos onde não deveriam estar acessíveis. O risco está em um invasor conseguir essas informações sem autenticação ou autorização adequadas, comprometendo a confidencialidade do sistema.

Exemplo

Uma API retorna a senha hash do usuário em resposta de erro, ou logs de produção contêm tokens de API visíveis em páginas de diagnóstico não protegidas, ou cookies de sessão aparecem em URLs refletidas em mensagens de erro.

Como mitigar

Implemente sanitização rigorosa de saídas (erros, logs, respostas HTTP), nunca exponha dados sensíveis em mensagens de erro ou debug, restrinja acesso a ferramentas diagnósticas com autenticação forte e revise regularmente logs e responses da API para dados confidenciais.

CVE-2025-61594LOWURI Credential Leakage Bypass over CVE-2025-27221EPSS 0.5%CVE-2026-42880CRITICALArgoCD ServerSideDiff is vulnerable to Kubernetes Secret ExtractionEPSS 0.5%CVE-2024-6055MEDIUMImproper removal of sensitive information in data source export feature in Devolutions Remote Desktop Manager 2024.1.32.0 and earlier on WinEPSS 0.5%CVE-2025-27221LOWIn the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication crEPSS 0.5%CVE-2026-40895MEDIUMfollow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect TargetsEPSS 0.5%CVE-2025-68131MEDIUMCBORDecoder reuse can leak shareable values across decode callsEPSS 0.4%CVE-2026-20928MEDIUMWindows Recovery Environment Security Feature Bypass VulnerabilityEPSS 0.4%CVE-2025-53886MEDIUMDirectus doesn't redact tokens in Flow logsEPSS 0.4%CVE-2024-41156LOWProfile files from TRO600 series radios are extracted in plain-text and encrypted file formats. Profile files provide potential attackers vaEPSS 0.4%CVE-2025-58049MEDIUMXWiki PDF export jobs store sensitive cookies unencrypted in job statusesEPSS 0.4%CVE-2026-45737MEDIUMArgo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotationsEPSS 0.4%CVE-2025-14267MEDIUMUnintended temporary cached data included in a structure only copy intended to be empty of dataEPSS 0.4%CVE-2024-43384HIGHPhoenix Contact: Improper removal of sensitive information in MGUARD productsEPSS 0.3%CVE-2023-52376HIGHInformation management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.EPSS 0.3%CVE-2026-43528HIGHOpenClaw < 2026.4.14 - Redaction Bypass via sourceConfig and runtimeConfig AliasesEPSS 0.3%CVE-2020-25635MEDIUMA flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is compleEPSS 0.3%CVE-2024-56353MEDIUMIn JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookiesEPSS 0.3%CVE-2022-23605MEDIUMExpired Ephemeral Messages not reliably removed in wire-webappEPSS 0.3%CVE-2025-57757MEDIUMContao discloses information in the news moduleEPSS 0.3%CVE-2026-27640HIGHtfplan2md has Sensitive Value Exposure in Generated ReportsEPSS 0.3%