Alert Tag: CWE-200

https://cwe.mitre.org/data/definitions/200.html

All of the alerts which use this tag:
ID Alert Status Risk Type
10103 Image Exposes Location or Privacy Data beta Informational Passive
100002 Server is running on Clacks - GNU Terry Pratchett alpha Informational Script Passive
100004 Content Security Policy Violations Reporting Enabled alpha Informational Script Passive
100012 Information Disclosure - IBAN Numbers alpha Low Script Passive
100013 Information Disclosure - Private IP Address alpha Medium Script Passive
100019 Information Disclosure - Server Header alpha Low Script Passive
100023 Information Disclosure - X-Powered-By Header alpha Low Script Passive
100034 Information Disclosure - Google API Key alpha Informational Script Passive
100036 Information Disclosure - Amazon S3 Bucket URL alpha Low Script Passive
200006-1 Credit Card Number beta Low Tool
200006-2 Social Security Number beta Low Tool
200009-1 JavaScript includes sourceMappingURL beta Low Tool
200009-2 HTML references .map files beta Low Tool
200009-3 Webpack dev-server / hot reload artifacts beta Low Tool
200009-4 Next.js build metadata exposed beta Low Tool
200011-1 Private key material exposed beta Low Tool
200011-2 AWS Access Key ID pattern beta Low Tool
200011-3 Slack token pattern beta Low Tool
200011-4 GitHub token pattern beta Low Tool
200011-5 Sentry DSN exposed beta Low Tool
200011-6 Firebase config exposed beta Low Tool
200011-7 Stripe publishable key exposed beta Low Tool
200011-8 Mapbox token exposed beta Low Tool
200011-9 Google API key pattern beta Low Tool
200012-1 Swagger UI detected beta Informational Tool
200012-2 OpenAPI spec detected beta Informational Tool
200012-3 API docs endpoint observed beta Informational Tool
200012-4 GraphQL endpoint observed beta Informational Tool
200012-5 GraphiQL / GraphQL Playground detected beta Informational Tool
200013-1 security.txt observed beta Informational Tool
200013-2 OIDC well-known configuration observed beta Informational Tool
200013-3 Android assetlinks.json observed beta Informational Tool
200013-4 Apple app-site-association observed beta Informational Tool
200016-1 Internal IP address leaked in response beta Low Tool
200016-2 localhost/127.0.0.1 referenced in response beta Low Tool
200016-3 Environment hints (dev/staging/test) in response beta Low Tool
200016-4 Cloud metadata IP referenced beta Low Tool
200019-1 Admin/management path observed beta Informational Tool
200019-2 Debug/diagnostic path observed beta Informational Tool
200019-3 Spring Boot actuator endpoint observed beta Informational Tool
200019-4 Swagger/OpenAPI path observed beta Informational Tool
200019-5 GraphQL path observed beta Informational Tool
200019-6 Potential backup file observed beta Informational Tool
200019-7 Environment/config file observed beta Informational Tool
200019-8 Potential .git exposure path observed beta Informational Tool
200019-9 phpinfo endpoint observed beta Informational Tool
210013-1 Exfiltration via fetch URL beta High Tool
210013-2 Exfiltration via fetch headers beta High Tool
210013-3 Exfiltration via XMLHttpRequest URL beta High Tool
210013-4 Exfiltration via XMLHttpRequest body beta High Tool
210013-5 Exfiltration via XMLHttpRequest headers beta High Tool
210013-6 Exfiltration via navigator.sendBeacon beta High Tool
210013-7 Exfiltration via image.src beacon beta Medium Tool