Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2022-32520HIGHA CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed oEPSS 0.5%CVE-2022-32518HIGHA CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed oEPSS 0.5%CVE-2022-43969CRITICALRicoh mp_c4504ex devices with firmware 1.06 mishandle credentials.EPSS 0.5%CVE-2022-43460HIGHDriver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains EPSS 0.5%CVE-2022-29089MEDIUMDell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. AEPSS 0.5%CVE-2026-23958HIGHDataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account TakeoverEPSS 0.5%CVE-2022-40685MEDIUMInsufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enableEPSS 0.5%CVE-2023-25740HIGHAfter downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unEPSS 0.5%CVE-2026-23742HIGHSkipper arbitrary code execution through lua filtersEPSS 0.5%CVE-2024-22345MEDIUMIBM TXSeries for Multiplatforms information disclosureEPSS 0.5%CVE-2024-34147MEDIUMJenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins contEPSS 0.5%CVE-2025-6519CRITICALConsistent predictable generation of the password for the default admin user "ONEDAY" to the application servicesEPSS 0.5%CVE-2024-8986CRITICALInformation Leakage in grafana-plugin-sdk-goEPSS 0.5%CVE-2025-64420CRITICALCoolify members can see private key of root userEPSS 0.5%CVE-2023-28764LOWInformation Disclosure vulnerability in SAP BusinessObjects PlatformEPSS 0.5%CVE-2026-69805HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-32988MEDIUMA missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission toEPSS 0.5%CVE-2022-41247MEDIUMJenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins cEPSS 0.5%CVE-2021-33589HIGHRibose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of EPSS 0.5%CVE-2023-31136LOWPostgresNIO processes unencrypted bytes from man-in-the-middleEPSS 0.5%