Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2025-23040MEDIUMMaliciously crafted remote URLs could lead to credential leak in GitHub DesktopEPSS 0.8%CVE-2020-5400HIGHCloud Controller logs environment variables from app manifestsEPSS 0.8%CVE-2023-41677HIGHA insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 EPSS 0.8%CVE-2021-41297HIGHECOA BAS controller - Insufficiently Protected Credentials-1EPSS 0.7%CVE-2022-30296HIGHInsufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated userEPSS 0.7%CVE-2020-8259Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.EPSS 0.7%CVE-2019-14840HIGHA flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentialsEPSS 0.7%CVE-2026-6253MEDIUMproxy credentials leak over redirect-to proxyEPSS 0.7%CVE-2020-15791MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-4EPSS 0.7%CVE-2024-29992MEDIUMAzure Identity Library for .NET Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43419MEDIUMJenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viEPSS 0.7%CVE-2022-23538MEDIUMUser credentials leaked to third-party service via HTTP redirect in scs-library-clientEPSS 0.7%CVE-2022-28291MEDIUMInsufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “neEPSS 0.7%CVE-2023-25413HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.EPSS 0.7%CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonaEPSS 0.7%CVE-2022-45384MEDIUMJenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the JenkinEPSS 0.7%CVE-2024-57395CRITICALPassword Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrarEPSS 0.7%CVE-2022-1766Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add EPSS 0.7%CVE-2022-45392MEDIUMJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the JenEPSS 0.7%CVE-2026-54617CRITICALGravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandlerEPSS 0.7%