目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-201 通过发送数据的信息暴露 类漏洞列表 391

CWE-201 通过发送数据的信息暴露 类弱点 391 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-201属于信息泄露类漏洞,指代码在向外部实体传输数据时,意外包含了不应被该实体访问的敏感信息。攻击者通常通过拦截网络流量或日志分析,窃取如密码、密钥或个人隐私等机密数据,进而实施身份伪造或进一步渗透。开发者应避免在日志、调试输出或API响应中记录敏感字段,采用数据最小化原则,并对传输内容进行加密与脱敏处理,确保仅传输必要且授权的信息。

MITRE CWE 官方描述
CWE:CWE-201 将敏感信息插入到发送数据中 英文:代码将数据发送给另一个实体,但数据的一部分包含该实体不应访问的敏感信息。
常见影响 (1)
Confidentiality Read Files or Directories, Read Memory, Read Application Data
Sensitive data may be exposed to attackers.
缓解措施 (4)
Requirements Specify which data in the software should be regarded as sensitive. Consider which types of users should have access to which types of data.
Implementation Ensure that any possibly sensitive data specified in the requirements is verified with designers to ensure that it is either a calculated risk or mitigated elsewhere. Any information that is not necessary to the functionality should be removed in order to lower both the overhead and the possibility of security sensitive data being sent.
System Configuration Setup default error messages so that unexpected errors do not disclose sensitive information.
Architecture and Design Compartmentalize the system to have "safe" areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area. Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separatio…
代码示例 (1)
The following is an actual MySQL error statement:
Warning: mysql_pconnect(): Access denied for user: 'root@localhost' (Using password: N1nj4) in /usr/local/www/wi-data/includes/database.inc on line 4
Result · SQL
CVE ID 标题 CVSS 风险等级 Published
CVE-2022-23488 BigBlueButton 安全漏洞 — bigbluebutton 6.5 Medium 2022-12-17
CVE-2020-8975 Zigor Corporación ZGR TPS200 NG 信息泄露漏洞 — ZGR TPS200 NG 7.5 High 2022-10-17
CVE-2020-27784 Linux kernel 资源管理错误漏洞 — kernel 7.1 - 2022-09-01
CVE-2022-27779 curl 安全漏洞 — https://github.com/curl/curl 5.3 - 2022-06-01
CVE-2022-27671 SAP Web dispatcher安全漏洞 — SAP BusinessObjects Business Intelligence Platform 6.5 - 2022-04-12
CVE-2022-0018 GlobalProtect 信息泄露漏洞 — GlobalProtect App 6.1 Medium 2022-02-10
CVE-2021-34771 Cisco IOS XR 信息泄露漏洞 — Cisco IOS XR Software 5.5 Medium 2021-09-09
CVE-2021-32653 Nextcloud 安全漏洞 — security-advisories 2.7 Low 2021-06-01
CVE-2020-27748 xdg-utils 安全漏洞 — xdg-utils 6.5 - 2021-06-01
CVE-2021-23019 F5 NGINX Controller 安全漏洞 — Nginx Controller 7.8 - 2021-06-01
CVE-2021-26566 Synology DiskStation Manager 信息泄露漏洞 — Synology DiskStation Manager (DSM) 8.3 High 2021-02-26
CVE-2021-1128 Cisco IOS和Cisco IOS XR 权限许可和访问控制问题漏洞 — Cisco IOS XR Software 5.5 Medium 2021-02-04
CVE-2021-1129 多款Cisco产品授权问题漏洞 — Cisco Web Security Appliance (WSA) 5.3 Medium 2021-01-20
CVE-2020-26085 Cisco Jabber 操作系统命令注入漏洞 — Cisco Jabber 9.9 Critical 2021-01-06
CVE-2020-27134 Cisco Jabber 信息泄露漏洞 — Cisco Jabber 9.9 Critical 2020-12-11
CVE-2020-27133 Cisco Jabber 授权问题漏洞 — Cisco Jabber 9.9 Critical 2020-12-11
CVE-2020-27132 Cisco Jabber 输入验证错误漏洞 — Cisco Jabber 9.9 Critical 2020-12-11
CVE-2020-27127 Cisco Jabber 安全漏洞 — Cisco Jabber 9.9 Critical 2020-12-11
CVE-2020-25703 Moodle 信息泄露漏洞 — moodle 5.3 - 2020-11-19
CVE-2020-14514 Power Line Communications Bus、PLC4TRUCKS和J2497 安全漏洞 — Trailer Power Line Communications 4.3 Medium 2020-09-01
CVE-2020-13597 Tigera Calico 信息泄露漏洞 — Calico 6.0 Medium 2020-06-03
CVE-2020-5364 Dell EMC Isilon OneFS 信息泄露漏洞 — Isilon OneFS 5.3 Medium 2020-05-20
CVE-2020-1774 OTRS Open Ticket Request System 安全漏洞 — ((OTRS)) Community Edition 4.5 Medium 2020-04-28
CVE-2020-1770 OTRS 信息泄露漏洞 — ((OTRS)) Community Edition 2.4 Low 2020-03-27
CVE-2019-15580 GitLab 信息泄露漏洞 — gitlab.com 7.5 - 2019-12-18
CVE-2019-14849 Red Hat 3scale 跨站脚本漏洞 — 3scale 5.4 - 2019-12-12
CVE-2018-17245 Elasticsearch Kibana 安全漏洞 — Kibana 9.1 - 2018-12-20
CVE-2017-2582 Red Hat Picketlink和KeyCloak 信息泄露漏洞 — keycloak 7.5 - 2018-07-26
CVE-2017-16026 Request 安全漏洞 — request node module 5.9 - 2018-06-04
CVE-2016-10518 ws模块安全漏洞 — ws node module 9.1 - 2018-05-31

CWE-201(通过发送数据的信息暴露) 是常见的弱点类别,本平台收录该类弱点关联的 391 条 CVE 漏洞。