Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2021-34560MEDIUMA vulnerability in WirelessHART-Gateway <= 3.0.9 could lead to information exposure of sensitive informationEPSS 0.2%CVE-2021-1537MEDIUMCisco ThousandEyes Recorder Information Disclosure VulnerabilityEPSS 0.2%CVE-2026-73839MEDIUMEbyte NE2-D11 Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-14790MEDIUMIBM InfoSphere Information Server is vulnerable to disclosure of sensitive informationEPSS 0.2%CVE-2026-28961MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attackEPSS 0.2%CVE-2025-66029HIGHOpen OnDemand affected by Apache proxy passing sensitive headersEPSS 0.2%CVE-2024-30119LOWHCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security HeaderEPSS 0.2%CVE-2022-26856HIGHDell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit tEPSS 0.2%CVE-2024-39278MEDIUMHughes Network Systems Insufficiently Protected CredentialsEPSS 0.2%CVE-2022-30944MEDIUMInsufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable EPSS 0.2%CVE-2025-58741HIGHInsecure Masked Credential Fields Enable Database Credential Access in Milner ImageDirector CaptureEPSS 0.2%CVE-2023-46115HIGHUpdater Private Keys Possibly Leaked via Vite Environment Variables in tauri-cliEPSS 0.2%CVE-2024-35192MEDIUMTrivy possibly leaks registry credential when scanning images from malicious registriesEPSS 0.2%CVE-2025-10360MEDIUMInsufficiently Protected Credentials in Puppet Enterprise 2025.4 and 2025.5EPSS 0.2%CVE-2022-29507MEDIUMInsufficiently protected credentials in the Intel(R) Team Blue mobile application in all versions may allow an authenticated user to potentiEPSS 0.2%CVE-2023-28084MEDIUMHPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokensEPSS 0.2%CVE-2022-26844HIGHInsufficiently protected credentials in the installation binaries for Intel(R) SEAPI in all versions may allow an authenticated user to poteEPSS 0.2%CVE-2023-6573MEDIUMHPE OneView may have a missing passphrase during restore.EPSS 0.2%CVE-2026-88013LOWrclone: http backend forwards custom/auth headers to a different host on redirectEPSS 0.2%CVE-2026-28714MEDIUMUnnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)EPSS 0.2%