Falhas do tipo CWE-297

60 resultados

Divulgação de Informações

Falha na proteção ou ocultação de dados sensíveis, permitindo que informações confidenciais (credenciais, tokens, dados pessoais, configurações internas) sejam acessadas por usuários não autorizados. O risco está na falta de controle de acesso, criptografia inadequada ou exposição acidental de dados em logs, mensagens de erro ou respostas da aplicação.

Exemplo

Uma API retorna detalhes completos de usuários (email, telefone, data de nascimento) em resposta a uma requisição que deveria retornar apenas o nome; ou um arquivo de configuração com senha do banco de dados fica acessível publicamente no servidor web; ou mensagens de erro expõem o caminho completo de arquivos do sistema e versões de softwares rodando.

Como mitigar

Implemente controle de acesso baseado em papéis (RBAC), minimize a quantidade de dados retornados em APIs (retorne apenas campos necessários), criptografe dados sensíveis em repouso e em trânsito (HTTPS obrigatório), sanitize mensagens de erro para não expor informações técnicas ao usuário final, e realize auditorias periódicas de logs e configurações para detectar exposições acidentais.

CVE-2026-48144CRITICALApache Thrift: c_glib TLS Client Missing Hostname VerificationEPSS 0.4%CVE-2026-34477MEDIUMApache Log4j Core: verifyHostName attribute silently ignored in TLS configuration, allowing hostname verification bypassEPSS 0.4%CVE-2024-8285MEDIUMKroxylicious: missing upstream kafka tls hostname verificationEPSS 0.4%CVE-2024-37015HIGHAn issue was discovered in Ada Web Server 20.0. When configured to use SSL (which is not the default setting), the SSL/TLS used to establishEPSS 0.4%CVE-2024-49782MEDIUMIBM OpenPages improper certificate validationEPSS 0.4%CVE-2024-38324MEDIUMIBM Storage Defender improper certificate validationEPSS 0.3%CVE-2026-42790HIGHnameConstraints DNS bypass via subject CommonName fallback in public_key hostname verificationEPSS 0.3%CVE-2025-59060MEDIUMApache Ranger: Hostname verification bypass in NiFiRegistryClient and NifiClientEPSS 0.3%CVE-2025-2190HIGHThe mobile application (com.transsnet.store) has a man-in-the-middle attack vulnerability, which may lead to code injection risks.EPSS 0.3%CVE-2018-19946MEDIUMThe vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerabilitEPSS 0.3%CVE-2026-66053MEDIUMApache Thrift: Python TSSLSocket Hostname Matcher ImportEPSS 0.3%CVE-2026-22747MEDIUMUnauthorized User Impersonation when Using X.509 Client CertificatesEPSS 0.3%CVE-2022-29082LOWDell EMC NetWorker versions 19.1.x, 19.1.0.x, 19.1.1.x, 19.2.x, 19.2.0.x, 19.2.1.x 19.3.x, 19.3.0.x, 19.4.x, 19.4.0.x, 19.5.x,19.5.0.x, 19.6EPSS 0.3%CVE-2026-59638CRITICALJSSE hostname verifier CN-fallback enabled by default despite documented opt-inEPSS 0.3%CVE-2026-58040MEDIUMAn incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incompEPSS 0.3%CVE-2026-54275LOWAIOHTTP: TLS Server Hostname Override Is Ignored When Reusing HTTPS ConnectionsEPSS 0.3%CVE-2022-48306MEDIUMGotham Chat IRC help does not validate hostnames in TLS certificatesEPSS 0.3%CVE-2023-34143MEDIUMImproper Validation of Certificate Vulnerability in Hitachi Device ManagerEPSS 0.2%CVE-2023-24568MEDIUM Dell NetWorker, contains an Improper Validation of Certificate with Host Mismatch vulnerability in Rabbitmq port which could disallow replaEPSS 0.2%CVE-2025-68637CRITICALApache Uniffle: Insecure SSL Configuration in Uniffle HTTP ClientEPSS 0.2%