Weaknesses of type CWE-522

690 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2024-34887MEDIUMInsufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAEPSS 0.3%CVE-2024-34882MEDIUMInsufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP accoEPSS 0.3%CVE-2024-27109HIGHInsufficiently protected credentials in GE HealthCare EchoPAC productsEPSS 0.3%CVE-2026-15977HIGHCVE-2026-15977EPSS 0.3%CVE-2024-47271MEDIUMInsufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575EPSS 0.3%CVE-2024-49364HIGHtiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environmentEPSS 0.3%CVE-2026-92759HIGHSecObserve before 1.59.1 Information Disclosure via API ConfigurationEPSS 0.3%CVE-2026-55431HIGHCoder's session token leaked to arbitrary hosts via `coder open app` for external workspace appsEPSS 0.3%CVE-2025-13163MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-13164MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-64998HIGHSession hijacking via exposed session signing secret in distributed Checkmk setupsEPSS 0.3%CVE-2024-21815CRITICAL Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticateEPSS 0.3%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.3%CVE-2025-0497HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.3%CVE-2017-2665MEDIUMThe skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.EPSS 0.3%CVE-2026-45091CRITICALsealed-env: TOTP secret embedded in unseal token payload (enterprise mode)EPSS 0.3%CVE-2020-8152Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decryEPSS 0.3%CVE-2023-50311LOWIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.3%CVE-2025-35941MEDIUMmySCADA PRO Manager Password DisclosureEPSS 0.3%CVE-2025-9521LOWPassword Confirmation Bypass in Omada ControllerEPSS 0.3%