Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2024-38453HIGHThe Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-EPSS 0.4%CVE-2025-26492HIGHIn JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resourcesEPSS 0.4%CVE-2025-30183HIGHCyberData 011209 SIP Emergency Intercom Insufficiently Protected CredentialsEPSS 0.4%CVE-2021-36204HIGHInsufficiently Protected Credentials in Metasys EPSS 0.4%CVE-2026-84179MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology PageEPSS 0.4%CVE-2026-82433MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UIEPSS 0.4%CVE-2024-42457HIGHA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combinatiEPSS 0.4%CVE-2024-4536MEDIUMEclipse EDC: OAuth2 Credential Exfiltration VulnerabilityEPSS 0.4%CVE-2023-23466MEDIUMMedia CP Media Control Panel – insufficiently protected credential changeEPSS 0.4%CVE-2025-55739MEDIUMapi: Shared OAuth Signing Key Between Different InstancesEPSS 0.4%CVE-2023-1518HIGHCP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently pEPSS 0.4%CVE-2020-37097HIGHEdimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)EPSS 0.4%CVE-2026-61802MEDIUMWazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configEPSS 0.4%CVE-2026-15806MEDIUM`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingEPSS 0.4%CVE-2026-9650HIGHCWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when uEPSS 0.4%CVE-2026-30796MEDIUMRustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat SyncEPSS 0.4%CVE-2021-43767Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'truEPSS 0.4%CVE-2022-2967MEDIUMProsys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credEPSS 0.4%CVE-2025-38739HIGHDell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated aEPSS 0.4%CVE-2024-22266MEDIUMVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.4%