Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2020-5263MEDIUMInformation disclosure through error objectEPSS 0.9%CVE-2017-0925Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration APEPSS 0.9%CVE-2023-33263HIGHIn WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE:EPSS 0.9%CVE-2022-4612MEDIUMClick Studios Passwordstate insufficiently protected credentialsEPSS 0.9%CVE-2014-1423MEDIUMOnline Accounts Signon daemon gives out all oauth tokens to any appEPSS 0.8%CVE-2026-48295HIGHCAI Content Credentials | Insufficiently Protected Credentials (CWE-522)EPSS 0.8%CVE-2018-16153HIGHAn issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts tEPSS 0.8%CVE-2021-27495Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.EPSS 0.8%CVE-2021-22640HIGHOvarro TBox Insufficiently Protected CredentialsEPSS 0.8%CVE-2022-41255MEDIUMJenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it canEPSS 0.8%CVE-2022-39168MEDIUMIBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.EPSS 0.8%CVE-2022-1666MEDIUMSecheron SEPCOS Control and Protection RelayEPSS 0.8%CVE-2024-0368HIGHHustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API KeysEPSS 0.8%CVE-2026-23658HIGHAzure DevOps: msazure Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-22998HIGHProtecting AWS credentials stored in plaintext on My Cloud HomeEPSS 0.8%CVE-2023-25407HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.EPSS 0.8%CVE-2021-3513A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wroEPSS 0.8%CVE-2022-41575HIGHA credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to EPSS 0.8%CVE-2024-7813MEDIUMSourceCodester Prison Management System Profile Image insufficiently protected credentialsEPSS 0.8%CVE-2021-36783CRITICALRancher: Failure to properly sanitize credentials in cluster template answersEPSS 0.8%