Weaknesses of type CWE-522

691 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2025-61482HIGHImproper handling of OTP/TOTP/HOTP values in NetKnights GmbH privacyIDEA Authenticator v.4.3.0 on Android allows local attackers with root aEPSS 0.1%CVE-2025-62312LOWHCL AION is affected by a vulnerability where basic authorization tokens are used for authenticationEPSS 0.1%CVE-2026-4387LOWUnencrypted storage of authentication state in StrongDM Desktop Application state.kv fileEPSS 0.1%CVE-2026-0290LOWPrisma Browser: Sensitive Information Disclosure VulnerabilityEPSS 0.1%CVE-2024-47588MEDIUMInformation Disclosure vulnerability in SAP NetWeaver Java (Software Update Manager)EPSS 0.1%CVE-2026-45407MEDIUMDokku: Git Credentials in .netrc Stored World-Readable Due to Premature touchEPSS 0.1%CVE-2020-9250LOWThere is an insufficient authentication vulnerability in some Huawei smart phone. An unauthenticated, local attacker can crafts software pacEPSS 0.1%CVE-2025-24508MEDIUMOffline Extraction of Account Connectivity Credentials (ACCs) in IT Management SuiteEPSS 0.1%CVE-2025-62794LOWGitHub Workflow Updater stored the optional Github token in plaintextEPSS 0.1%CVE-2025-40751MEDIUMA vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report ClEPSS 0.1%CVE-2023-43635HIGHVault Key Sealed With SHA1 PCRsEPSS 0.1%CVE-2026-20435MEDIUMIn preloader, there is a possible read of device unique identifiers due to a logic error. This could lead to local information disclosure, iEPSS 0.1%CVE-2023-43630HIGHConfig Partition Not Measured From 2 FrontsEPSS 0.1%CVE-2024-29941HIGHCredential CloningEPSS 0.1%CVE-2021-47759MEDIUMMTPutty 1.0.1.21 - SSH Password DisclosureEPSS 0.1%CVE-2023-4327—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2023-4328—Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are accessible to any local user on LinuxEPSS 0.1%CVE-2025-36568HIGHDell PowerProtect Data Domain BoostFS for client of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.EPSS 0.1%CVE-2025-6571MEDIUMA 3rd-party component exposed its password in process arguments, allowing for low-privileged users to access it.EPSS 0.1%CVE-2025-15621MEDIUMSparx Enterprise Architect Client does not verify the receiver of OAuth2 credentials during OpenID authenticationEPSS 0.1%