Weaknesses of type CWE-311

312 results

Ausência de criptografia de dados sensíveis

Quando dados sensíveis (senhas, tokens, PII, chaves) são transmitidos ou armazenados sem criptografia, qualquer pessoa com acesso à rede ou ao disco consegue lê-los diretamente. O risco é grave porque expõe informações críticas a interceptação ou roubo.

Example

Uma aplicação web envia credenciais de usuário em HTTP plano em vez de HTTPS, ou salva senhas em um arquivo de texto sem criptografar. Um atacante na mesma rede (ou com acesso ao servidor) captura as credenciais facilmente.

How to mitigate

Use HTTPS/TLS para toda transmissão de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), implemente gestão segura de chaves e nunca armazene ou transmita dados sensíveis em claro. Revise logs e backups também.

CVE-2016-10679selenium-standalone-painful installs a start-selenium command line to start a standalone selenium server with chrome-driver. selenium-standaEPSS 2.0%CVE-2016-10588nw is an installer for nw.js. nw downloads zipped resources over HTTP, It may be possible to cause remote code execution (RCE) by swapping oEPSS 1.8%CVE-2016-10603air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. ItEPSS 1.8%CVE-2016-10633dwebp-bin is a dwebp node.js wrapper that convert WebP into PNG. dwebp-bin downloads binary resources over HTTP, which leaves it vulnerable EPSS 1.8%CVE-2016-10677google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-EPSS 1.8%CVE-2016-10569embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 dowEPSS 1.8%CVE-2016-10589selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vEPSS 1.8%CVE-2016-10693pm2-kafka is a PM2 module that installs and runs a kafka server pm2-kafka downloads binary resources over HTTP, which leaves it vulnerable tEPSS 1.8%CVE-2016-10698mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources over HTTP, which leavEPSS 1.8%CVE-2016-10634scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable EPSS 1.8%CVE-2016-10650ntfserver is a Network Testing Framework Server. ntfserver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 1.8%CVE-2016-10648marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources oEPSS 1.8%CVE-2016-10591Prince is a Node API for executing XML/HTML to PDF renderer PrinceXML via prince(1) CLI. prince downloads zipped resources over HTTP, which EPSS 1.8%CVE-2016-10586macaca-chromedriver is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver before 1.0.29 downloads binary resources over HTEPSS 1.8%CVE-2016-10647node-air-sdk is an AIR SDK for nodejs. node-air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It mayEPSS 1.8%CVE-2016-10684healthcenter - IBM Monitoring and Diagnostic Tools health Center agent healthcenter downloads binary resources over HTTP, which leaves it vuEPSS 1.8%CVE-2016-10687windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources oveEPSS 1.8%CVE-2016-10636grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITMEPSS 1.8%CVE-2016-10627scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may EPSS 1.8%CVE-2016-10611strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable tEPSS 1.8%