Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2023-28089HIGHAn HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect ModulesEPSS 0.2%CVE-2024-23551MEDIUMHCL BigFix Compliance is potentially affected by Oracle database credentials stored at endpointEPSS 0.2%CVE-2022-0019MEDIUMGlobalProtect App: Insufficiently Protected Credentials Vulnerability on LinuxEPSS 0.2%CVE-2026-49449LOWJoplin: KaTeX `trust:true` enables URL-allowlist bypass leading to NTLMv2 credential theft via UNC path on WindowsEPSS 0.2%CVE-2024-43812HIGHKieback&Peter DDC4000 Series Path Traversal Insufficiently Protected CredentialsEPSS 0.2%CVE-2021-38938MEDIUMIBM Host Access Transformation Services information disclosureEPSS 0.2%CVE-2026-2255MEDIUMHitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-3480MEDIUMMedDream WEB DICOM Viewer Cleartext Transmission of Credentials Information Disclosure VulnerabilityEPSS 0.2%CVE-2024-38282HIGHInsufficiently Protected Credentials in Motorola Solutions Vigilant Fixed LPR Coms Box (BCAV1F2-C600)EPSS 0.2%CVE-2025-52623LOWHCL AION is affected by an Autocomplete HTML Attribute Not Disabled for Password Field vulnerabilityEPSS 0.2%CVE-2026-75136MEDIUMUpSignOn < 7.19.0 Biometric Key Exposure via Windows PasswordVaultEPSS 0.2%CVE-2025-54808HIGHOxford Nanopore Technologies MinKNOW Insufficiently Protected CredentialsEPSS 0.2%CVE-2024-42192MEDIUMHCL Traveler for Microsoft Outlook (HTMO) is susceptible to a credential leakageEPSS 0.2%CVE-2024-23583MEDIUMHCL BigFix Platform is susceptible to insufficiently protected credentialsEPSS 0.2%CVE-2026-14354HIGHCWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modificEPSS 0.2%CVE-2025-15622MEDIUMSparx Enterprise Architect Client reveals plaintext OAuth2 client secretEPSS 0.2%CVE-2023-23370MEDIUMQVPN Device ClientEPSS 0.2%CVE-2024-9677MEDIUMThe insufficiently protected credentials vulnerability in the CLI command of the USG FLEX H series uOS firmware version V1.21 and earlier veEPSS 0.2%CVE-2024-23306HIGHBIG-IP Next CNF & SPK vulnerabilityEPSS 0.2%CVE-2025-34062MEDIUMOneLogin AD Connector API Credential and Signing Key ExposureEPSS 0.2%