Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2024-46480HIGHAn NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privEPSS 0.5%CVE-2023-32280MEDIUMInsufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated EPSS 0.5%CVE-2023-1574MEDIUMInformation disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on WindoEPSS 0.5%CVE-2025-27192LOWAdobe Commerce | Insufficiently Protected Credentials (CWE-522)EPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2025-34196CRITICALVasion Print (formerly PrinterLogic) Hardcoded PrinterLogic CA Private Key and Hardcoded PasswordEPSS 0.5%CVE-2023-25531HIGHNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploEPSS 0.5%CVE-2024-5176CRITICALVulnerability in Welch Allyn Configuration Tool SoftwareEPSS 0.5%CVE-2026-64918MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 0.5%CVE-2023-29168LOWPTC Vuforia Studio Insufficiently Protected CredentialsEPSS 0.5%CVE-2023-31187MEDIUMAvaya IX Workforce Engagement - CWE-522: Insufficiently Protected CredentialsEPSS 0.5%CVE-2026-59891CRITICALCredential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registryEPSS 0.5%CVE-2026-32633CRITICALGlances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`EPSS 0.5%CVE-2022-41564MEDIUMTIBCO Operational Intelligence Hawk Redtail Credential Exposure VulnerabilityEPSS 0.5%CVE-2024-41771HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2019-17082CRITICALInsufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris sEPSS 0.5%CVE-2024-41770HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2025-52549CRITICALPredictable root linux password generationEPSS 0.5%CVE-2022-26341HIGHInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R)EPSS 0.5%CVE-2025-62157HIGHArgo Workflows exposes artifact repository credentials in workflow-controller logsEPSS 0.5%