Weaknesses of type CWE-522

689 results

Credenciais insuficientemente protegidas

Quando credenciais (senhas, tokens, chaves) são armazenadas, transmitidas ou processadas sem criptografia ou com proteção inadequada, ficam expostas a roubo. Um atacante que acessa o código-fonte, logs, memória ou intercepta a comunicação consegue recuperar as credenciais e usá-las para comprometer sistemas.

Example

Guardar senha em plain text no arquivo de configuração, enviar token em URL de GET em vez de POST/body criptografado, ou exibir credenciais completas em log de erro são exemplos clássicos. Se a chave de API está no repositório Git ou a senha no console, qualquer pessoa com acesso ao código a recupera.

How to mitigate

Nunca armazene credenciais em plain text — use variáveis de ambiente, secret managers (Vault, AWS Secrets Manager) ou bases de dados com criptografia. Na transmissão, force HTTPS/TLS. Em logs e mensagens de erro, mascare ou remova dados sensíveis. Implemente rotação de credenciais e use autenticação multi-fator quando possível.

CVE-2023-32687HIGHInsufficiently Protected ChatBot Credentials in tgstation-serverEPSS 0.6%CVE-2023-44158LOWSensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (LinEPSS 0.6%CVE-2024-40704MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.6%CVE-2025-0867CRITICALPrivilege Escalation in MEAC300EPSS 0.6%CVE-2022-40751MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.6%CVE-2026-62839MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2025-54863CRITICALInsufficiently Protected Credentials in Radiometrics VizAirEPSS 0.6%CVE-2025-32963MEDIUMMinio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STSEPSS 0.6%CVE-2026-62882MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 0.6%CVE-2023-3251MEDIUMPass-back vulnerability in NessusEPSS 0.6%CVE-2026-81381MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-25191HIGHAMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.EPSS 0.6%CVE-2022-37193HIGHChipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from aEPSS 0.6%CVE-2024-26330MEDIUMAn issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while theEPSS 0.6%CVE-2024-6492HIGHExposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on WinEPSS 0.6%CVE-2026-77909HIGHAzure CycleCloud Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-47805HIGHJenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentiEPSS 0.6%CVE-2019-10225A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently prEPSS 0.6%CVE-2022-38714MEDIUMIBM DataStage on Cloud Pak for Data information disclosureEPSS 0.6%