Weaknesses of type CWE-319

539 results

Transmissão de dados sensíveis em texto plano

A aplicação envia informações críticas (senhas, tokens, dados pessoais) sem criptografia em canais de comunicação que podem ser interceptados. Um atacante na rede consegue capturar esses dados diretamente, comprometendo a confidencialidade da informação e permitindo roubo de credenciais ou dados sensíveis.

Example

Um app mobile envia login e senha via HTTP (não HTTPS), ou um sistema transmite números de cartão de crédito em requisições não criptografadas. Ferramentas simples como Wireshark permitem capturar esse tráfego em redes abertas ou mesmo corporativas.

How to mitigate

Sempre usar HTTPS/TLS para qualquer transmissão de dados sensíveis, implementar pinning de certificado em apps mobile, validar certificados no lado cliente, e nunca transmitir segredos em URLs ou headers sem criptografia. Na prática: configure HTTPS em produção, force redirecionamento HTTP → HTTPS, e audite logs de requisições para detectar canais desprotegidos.

CVE-2025-57727MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote referenceEPSS 0.2%CVE-2024-8059MEDIUMIPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.EPSS 0.2%CVE-2025-44612MEDIUMTinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device creEPSS 0.2%CVE-2019-6540MEDIUMMedtronic Conexus Radio Frequency Telemetry Protocol Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-27752HIGHSODOLA SL902-SWTGW124AS <= 200.1.20 Cleartext Credential TransmissionEPSS 0.2%CVE-2025-44251HIGHEcovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.EPSS 0.2%CVE-2023-24440MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins cEPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2025-13489MEDIUMIBM DevOps Deploy is susceptible to a Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2026-40431MEDIUMSenseLive X3050 Cleartext transmission of sensitive informationEPSS 0.2%CVE-2025-12508HIGHUnencrypted communication to Active Directory servicesEPSS 0.2%CVE-2026-81836MEDIUMRooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmissionEPSS 0.2%CVE-2026-33569MEDIUMAnviz Products Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-13490MEDIUMIBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentialityEPSS 0.2%CVE-2025-64648MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-43625HIGHCodexBar < 0.32.0 Session Cookie Exposure via HTTP RedirectEPSS 0.2%CVE-2026-50200HIGHSteeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsEPSS 0.2%CVE-2025-70048HIGHAn issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.2%CVE-2025-13718LOWIBM Sterling Partner Engagement Manager Information DisclosureEPSS 0.2%CVE-2026-88013LOWrclone: http backend forwards custom/auth headers to a different host on redirectEPSS 0.2%