Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2020-10755MEDIUMAn insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versionsEPSS 1.2%CVE-2018-8858If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) theEPSS 1.2%CVE-2021-28171CRITICALVangene deltaFlow E-platform - Broken AuthenticationEPSS 1.2%CVE-2021-3344A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mountEPSS 1.2%CVE-2017-5189MEDIUMprivate SSL key embedded in JAR file in iManagerEPSS 1.2%CVE-2023-29055HIGHApache Kylin: Insufficiently protected credentials in config fileEPSS 1.1%CVE-2022-46967CRITICALAn access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directorEPSS 1.1%CVE-1999-0013HIGHStolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent uEPSS 1.1%CVE-2019-13421Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configuEPSS 1.1%CVE-2019-5648HIGHLDAP Credential Exposure in Barracuda Load Balancer ADCEPSS 1.1%CVE-2024-40710HIGHA series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extractiEPSS 1.1%CVE-2021-27491Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.EPSS 1.1%CVE-2021-28813CRITICALInsufficiently Protected Credentials Vulnerability in QSW-M2116P-2T2S and QuNetSwitchEPSS 1.1%CVE-2025-4679MEDIUMA vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecEPSS 1.1%CVE-2021-1232MEDIUMCisco SD-WAN vManage Information Disclosure VulnerabilityEPSS 1.1%CVE-2020-7030MEDIUMIPO Information DisclosureEPSS 1.0%CVE-2023-35348MEDIUMActive Directory Federation Service Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2021-20997HIGHWAGO: Managed Switches: Unauthorized access to password hashesEPSS 1.0%CVE-2020-5406PCF Autoscaling logs its database credentialsEPSS 1.0%CVE-2017-13998An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficientEPSS 1.0%