Weaknesses of type CWE-311

312 results

Ausência de criptografia de dados sensíveis

Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.

Example

Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.

How to mitigate

Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.

CVE-2025-53659MEDIUMJenkins QMetry Test Management Plugin 1.13 and earlier stores Qmetry Automation API Keys unencrypted in job config.xml files on the Jenkins EPSS 0.2%CVE-2025-53678MEDIUMJenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins contEPSS 0.2%CVE-2025-53673MEDIUMJenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration filEPSS 0.2%CVE-2025-53676MEDIUMJenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controlleEPSS 0.2%CVE-2020-7567HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attEPSS 0.2%CVE-2024-23444MEDIUMElasticsearch elasticsearch-certutil csr fails to encrypt private keyEPSS 0.2%CVE-2024-25631MEDIUMUnencrypted traffic between pods when using Wireguard and an external kvstoreEPSS 0.2%CVE-2026-81688HIGHopenssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256EPSS 0.2%CVE-2025-53653MEDIUMJenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the JenkinsEPSS 0.2%CVE-2023-30561MEDIUMLack of Cryptographic Security of IUI Bus EPSS 0.2%CVE-2024-40620MEDIUMRockwell Automation Pavilion8® Unencrypted Data Vulnerability via HTTP protocolEPSS 0.2%CVE-2024-25630MEDIUMCilium has unencrypted ingress/health traffic when using Wireguard transparent encryptionEPSS 0.2%CVE-2025-64143MEDIUMJenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controllEPSS 0.2%CVE-2026-53442MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job confEPSS 0.2%CVE-2023-28045MEDIUM Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could EPSS 0.2%CVE-2023-6339CRITICALGoogle Nest WiFi Pro root code-execution & user-data compromiseEPSS 0.2%CVE-2018-8864—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vuEPSS 0.2%CVE-2024-47871HIGHInsecure communication between the FRP client and server in GradioEPSS 0.2%CVE-2020-9062—Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2024-28250MEDIUMCilium has possible unencrypted traffic between nodes when using WireGuard and L7 policiesEPSS 0.2%