Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2026-33575HIGHOpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup CodesEPSS 0.2%CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.2%CVE-2019-10139MEDIUMDuring HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleEPSS 0.2%CVE-2026-0393MEDIUMCODESYS Visualization - Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-53657MEDIUMJenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed oEPSS 0.2%CVE-2025-53660MEDIUMJenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, incEPSS 0.2%CVE-2026-27777MEDIUMMobiliti e-mobi.hu Insufficiently Protected CredentialsEPSS 0.2%CVE-2026-54660HIGHswagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`EPSS 0.2%CVE-2026-76846HIGHGrav before 2.0.16 Information Disclosure via Twig SandboxEPSS 0.2%CVE-2026-72793CRITICALSiYuan before v3.7.4 Information Disclosure via /api/system/getConfEPSS 0.2%CVE-2026-72801HIGHSiYuan before v3.7.4 Information Disclosure via Encryption Key MaterialEPSS 0.2%CVE-2025-53661MEDIUMJenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing EPSS 0.2%CVE-2026-71511HIGHDolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member EndpointsEPSS 0.2%CVE-2026-14564CRITICALSensitive Data Exposure in Innotim Software's Logsign SIEMEPSS 0.2%CVE-2026-82070HIGHInsufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceEPSS 0.2%CVE-2022-33954MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.2%CVE-2023-50436MEDIUMAn issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The eEPSS 0.2%CVE-2025-69271LOWSpectrum basic authentication in useEPSS 0.2%CVE-2026-28961MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attackEPSS 0.2%CVE-2021-22781—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%