Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2024-36127HIGHapko Exposure of HTTP basic auth credentials in log outputEPSS 0.4%CVE-2026-62214MEDIUMOpenClaw < 2026.5.28 Bot Framework SSRF via serviceUrl Parameter ValidationEPSS 0.4%CVE-2026-32171HIGHAzure Logic Apps Elevation of Privilege VulnerabilityEPSS 0.4%CVE-2020-28390A vulnerability has been identified in Opcenter Execution Core (V8.2), Opcenter Execution Core (V8.3). The application contains an informatiEPSS 0.4%CVE-2026-42869CRITICALSOCFortress CoPilot: Hardcoded JWT secret allows unauthenticated full admin compromise and lateral movement into all integrated SOC toolsEPSS 0.4%CVE-2022-45157HIGHExposure of vSphere's CPI and CSI credentials in RancherEPSS 0.4%CVE-2025-64898MEDIUMColdFusion | Insufficiently Protected Credentials (CWE-522)EPSS 0.4%CVE-2026-50017MEDIUMpnpm binds unscoped user-level npm auth credentials to a repository-selected registryEPSS 0.4%CVE-2025-58130CRITICALApache Fineract: Server Key not maskedEPSS 0.4%CVE-2024-51545CRITICALUsername EnumerationEPSS 0.4%CVE-2026-53632MEDIUMNTLMv2 hash disclosure via UNC path handling on WindowsEPSS 0.4%CVE-2024-34885MEDIUMInsufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to read SMTP accoEPSS 0.4%CVE-2026-44622MEDIUMEVoke Systems EVoke CSMS Insufficiently Protected CredentialsEPSS 0.4%CVE-2017-16718Beckhoff TwinCAT 3 supports communication over ADS. ADS is a protocol for industrial automation in protected environments. This protocol useEPSS 0.4%CVE-2026-55215HIGHMariaDB Connector/Node.js: Connector leaks the cleartext password to an MitM despite `ssl: true`EPSS 0.4%CVE-2026-1223MEDIUMBROWAN COMMUNICATIONS |PrismX MX100 AP controller - Insufficiently Protected CredentialsEPSS 0.4%CVE-2024-50699HIGHTP-Link TL-WR845N(UN)_V4_201214, TL-WR845N(UN)_V4_200909 and TL-WR845N(UN)_V4_190219 were discovered to contain weak default credentials forEPSS 0.4%CVE-2026-44979MEDIUM@hapi/wreck : Sensitive `Proxy-Authorization` header leaked across cross-hostname redirectsEPSS 0.4%CVE-2025-0619MEDIUMUnsafe stored password recoveryEPSS 0.4%CVE-2026-33182MEDIUMSaloon is vulnerable to SSRF and credential leakage via absolute URL in endpoint overriding base URLEPSS 0.4%