CWE-200 信息暴露 类弱点 3396 条 CVE 漏洞汇总,含 AI 中文分析。
CWE-200 指产品向未授权主体暴露敏感信息,属于信息泄露类漏洞。攻击者常通过未加密通信、错误日志记录或调试接口获取密钥、用户数据等机密内容。开发者应避免在日志中记录敏感字段,实施最小权限原则,对传输数据进行加密,并严格限制调试模式的访问权限,从而有效防止信息被非法窃取。
my $username=param('username'); my $password=param('password'); if (IsValidUsername($username) == 1) { if (IsValidPassword($username, $password) == 1) { print "Login Successful"; } else { print "Login Failed - incorrect password"; } } else { print "Login Failed - unknown username"; }
"Login Failed - incorrect username or password"
try { openDbConnection(); } //print exception message that includes exception message and configuration file location catch (Exception $e) { echo 'Caught exception: ', $e->getMessage(), '\n'; echo 'Check credentials in config file at: ', $Mysql_config_location, '\n'; }
| CVE ID | 标题 | CVSS | 风险等级 | Published |
|---|---|---|---|---|
| CVE-2019-3993 | ELOG 信息泄露漏洞 — ELOG | 7.5 | - | 2019-12-17 |
| CVE-2019-3992 | ELOG 信息泄露漏洞 — ELOG | 7.5 | - | 2019-12-17 |
| CVE-2019-18332 | Siemens SPPA-T3000 授权问题漏洞 — SPPA-T3000 Application Server | 5.3 | - | 2019-12-12 |
| CVE-2019-18333 | Siemens SPPA-T3000 信息泄露漏洞 — SPPA-T3000 Application Server | 5.3 | - | 2019-12-12 |
| CVE-2019-18334 | Siemens SPPA-T3000 信息泄露漏洞 — SPPA-T3000 Application Server | 5.3 | - | 2019-12-12 |
| CVE-2019-18335 | Siemens SPPA-T3000 信息泄露漏洞 — SPPA-T3000 Application Server | 5.3 | - | 2019-12-12 |
| CVE-2019-18331 | Siemens SPPA-T3000 信息泄露漏洞 — SPPA-T3000 Application Server | 5.3 | - | 2019-12-12 |
| CVE-2019-10217 | Ansible 信息泄露漏洞 — Ansible | 6.5 | - | 2019-11-25 |
| CVE-2019-6852 | 多款Schneider Electric产品信息泄露漏洞 — Modicon Controllers (M340 CPUs, M340 communication modules, Premium CPUs, Premium communication modules, Quantum CPUs, Quantum communication modules - see security notification for specific versions) | 7.5 | - | 2019-11-20 |
| CVE-2019-13557 | Philips Tasy EMR和Tasy WebPortal 信息泄露漏洞 — Tasy EMR | 5.3 | - | 2019-11-08 |
| CVE-2019-1877 | Cisco Enterprise Chat and Email 信息泄露漏洞 — Cisco Enterprise Chat and Email | 7.5 | - | 2019-11-05 |
| CVE-2019-1734 | Cisco FXOS Software和Cisco NX-OS Software 信息泄露漏洞 — Cisco NX-OS Software | 5.5 | - | 2019-11-05 |
| CVE-2019-10223 | kube-state-metrics 信息泄露漏洞 — kube-state-metrics | 4.9 | - | 2019-11-05 |
| CVE-2019-17321 | ClipSoft REXPERT 信息泄露漏洞 — REXPERT | 5.3 | - | 2019-10-30 |
| CVE-2019-7619 | Elasticsearch 加密问题漏洞 — Elasticsearch | 5.3 | - | 2019-10-30 |
| CVE-2019-6850 | 多款Schneider Electric产品信息泄露漏洞 — Modicon M580, Modicon BMENOC 0311, Modicon BMENOC 0321 | 7.5 | - | 2019-10-29 |
| CVE-2019-6849 | Schneider Electric Modicon M580、Modicon BMENOC 0311和BMENOC 0321 信息泄露漏洞 — Modicon M580, Modicon BMENOC 0311, Modicon BMENOC 0321 | 7.5 | - | 2019-10-29 |
| CVE-2019-11282 | Cloud Foundry UAA 注入漏洞 — UAA Release | 4.3 | - | 2019-10-23 |
| CVE-2019-13410 | TOPMeeting 信息泄露漏洞 — TOPMeeting | 7.5 | - | 2019-10-17 |
| CVE-2019-15257 | Cisco SPA100 Series Analog Telephone Adapters 信息泄露漏洞 — Cisco SPA112 2-Port Phone Adapter | 6.5 | - | 2019-10-16 |
| CVE-2019-12708 | Cisco SPA100 Series Analog Telephone Adapters 信息泄露漏洞 — Cisco SPA112 2-Port Phone Adapter | 6.5 | - | 2019-10-16 |
| CVE-2019-12704 | Cisco SPA100 Series Analog Telephone Adapters 信息泄露漏洞 — Cisco SPA112 2-Port Phone Adapter | 6.5 | - | 2019-10-16 |
| CVE-2019-3767 | Dell ImageAssist 信息泄露漏洞 — ImageAssist | 6.0 | - | 2019-10-14 |
| CVE-2019-13523 | 霍尼韦尔 Honeywell Performance HEN08104 访问控制错误漏洞 — Performance IP Cameras | 5.3 | - | 2019-09-26 |
| CVE-2019-12664 | Cisco 4000 Series Integrated Services Routers IOS XE 信息泄露漏洞 — Cisco IOS XE Software | 6.5 | - | 2019-09-25 |
| CVE-2019-5463 | GitLab 授权问题漏洞 — GitLab CE/EE | 4.3 | - | 2019-09-09 |
| CVE-2019-1976 | Cisco Industrial Network Director 信息泄露漏洞 — Cisco Industrial Network Director | 9.8 | - | 2019-09-05 |
| CVE-2019-11064 | AndroVideo Advan VD-1 授权问题漏洞 — Advan VD-1 firmware | 9.8 | - | 2019-08-29 |
| CVE-2019-1908 | Cisco UCS C-Series Servers和UCS S-Series Servers 信息泄露漏洞 — Cisco Unified Computing System (Management Software) | 7.5 | - | 2019-08-21 |
| CVE-2019-13511 | 罗克韦尔 Rockwell Automation Arena Simulation Software 资源管理错误漏洞 — Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier | 3.3 | - | 2019-08-15 |
CWE-200(信息暴露) 是常见的弱点类别,本平台收录该类弱点关联的 3396 条 CVE 漏洞。