Falhas do tipo CWE-668

217 resultados

Divulgação de Informações

A aplicação expõe dados sensíveis (senhas, tokens, dados pessoais, configurações internas) através de canais inadequados: mensagens de erro verbosas, logs acessíveis, memória não limpa, headers HTTP desnecessários ou comportamentos diferenciados que vazam pistas. O risco está em que um atacante consegue reunir informações que facilitam outros ataques ou violam privacidade.

Exemplo

Um endpoint retorna 'Usuário não encontrado no banco de dados' em vez de apenas 'Credenciais inválidas', permitindo que alguém enumere usuários válidos; ou a aplicação deixa tokens JWT em cookies acessíveis ao JavaScript malicioso; ou logs de erro com stack traces são servidos publicamente.

Como mitigar

Sanitize mensagens de erro (respostas genéricas ao usuário final, logs detalhados apenas em backend seguro); revise headers HTTP (remova versões de software, X-Powered-By); nunca armazene segredos em código-fonte, variáveis de ambiente ou comentários; implemente rotação e expiração de tokens; configure logs com controle de acesso restrito e sem dados sensíveis em strings de debug.

CVE-2022-35936HIGHEthermint DoS through Unintended Contract SelfdestructEPSS 1.4%CVE-2021-44523A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2021-44522A vulnerability has been identified in SiPass integrated V2.76 (All versions), SiPass integrated V2.80 (All versions), SiPass integrated V2.EPSS 1.4%CVE-2023-29355MEDIUMDHCP Server Service Information Disclosure VulnerabilityEPSS 1.3%CVE-2023-31103HIGHApache InLong: Attackers can change the immutable name and type of clusterEPSS 1.3%CVE-2023-34189Apache InLong: General user can delete and update processEPSS 1.3%CVE-2020-5386HIGHDell EMC ECS, versions prior to 3.5, contains an Exposure of Resource vulnerability. A remote unauthenticated attacker can access the list oEPSS 1.3%CVE-2023-39478MEDIUMSofting Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution VulnerabilityEPSS 1.3%CVE-2023-31206HIGHApache InLong: Attackers can change the immutable name and type of nodesEPSS 1.2%CVE-2023-26081HIGHIn Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandEPSS 1.2%CVE-2022-45438MEDIUMApache Superset: Dashboard metadata information leakEPSS 1.2%CVE-2021-21878MEDIUMA local file inclusion vulnerability exists in the Web Manager Applications and FsBrowse functionality of Lantronix PremierWave 2050 8.9.0.0EPSS 1.2%CVE-2021-22869Improper access control in GitHub Enterprise Server allows self-hosted runners to execute outside their control groupEPSS 1.2%CVE-2021-23264HIGHTransmission of Private Resources into a New Sphere ('Resource Leak') and Exposure of Resource to Wrong Sphere in Crafter SearchEPSS 1.1%CVE-2022-48198CRITICALThe ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code oEPSS 1.1%CVE-2023-39171HIGHSENEC Storage Box V1,V2 and V3 accidentially expose a management interfaceEPSS 1.1%CVE-2022-22515HIGHA component of the CODESYS Control runtime system allows read and write access to configuration filesEPSS 1.1%CVE-2021-39184MEDIUMSandboxed renderers can obtain thumbnails of arbitrary files through the nativeImage APIEPSS 1.1%CVE-2022-24823MEDIUMLocal Information Disclosure Vulnerability in io.netty:netty-codec-httpEPSS 1.0%CVE-2022-24074Whale Bridge, a default extension in Whale browser before 3.12.129.18, allowed to receive any SendMessage request from the content script itEPSS 1.0%