Weaknesses of type CWE-540

31 results

Exposição de informações sensíveis no código-fonte

Desenvolvedores deixam credenciais, tokens, chaves de API, URLs internas ou dados confidenciais hardcoded diretamente no código-fonte ou em arquivos de configuração versionados. Quando o repositório (ou backup) vaza, esses segredos ficam acessíveis a qualquer pessoa com acesso ao código.

Example

Um arquivo .py com `db_password = "admin123"` ou `.env` commitado no Git; uma variável de configuração em Java com `api_key = "sk-abc123xyz"` visível no histórico do repositório; ou uma string de conexão SQL em código comentado.

How to mitigate

Nunca commite segredos no versionamento — use variáveis de ambiente ou vaults (HashiCorp Vault, AWS Secrets Manager). Implemente pre-commit hooks para bloquear padrões suspeitos (regex para detectar chaves). Se já foi exposto, regenere as credenciais imediatamente e verifique logs de acesso.

CVE-2021-34638MEDIUMWordPress Download Manager <= 3.1.24 Authenticated Directory TraversalEPSS 1.3%CVE-2021-1516MEDIUMCisco Content Security Management Appliance, Email Security Appliance, and Web Security Appliance Information Disclosure VulnerabilityEPSS 1.2%CVE-2024-2265MEDIUMkeerti1924 PHP-MYSQL-User-Login-System login.sql inclusion of sensitive information in source codeEPSS 0.8%CVE-2023-23448MEDIUMInclusion of Sensitive Information in Source Code in SICK FTMg AIR FLOW SENSOR with Partnumbers 1100214, 1100215, 1100216, 1120114, 1120116,EPSS 0.8%CVE-2021-34744MEDIUMCisco Business 220 Series Smart Switches Static Key and Password VulnerabilitiesEPSS 0.7%CVE-2024-8417LOW云课网络科技有限公司 Yunke Online School System videobind.html sensitive information in sourceEPSS 0.7%CVE-2023-30802MEDIUMSangfor Next-Gen Application Firewall Source Code DisclosureEPSS 0.6%CVE-2024-38647HIGHQNAP AI CoreEPSS 0.6%CVE-2024-2355LOWkeerti1924 Secret-Coder-PHP-Project secret_coder.sql inclusion of sensitive information in source codeEPSS 0.6%CVE-2021-34757MEDIUMCisco Business 220 Series Smart Switches Static Key and Password VulnerabilitiesEPSS 0.6%CVE-2026-4155HIGHChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure VulnerabilityEPSS 0.6%CVE-2025-49182HIGHCredential disclosureEPSS 0.5%CVE-2024-39729MEDIUMIBM Datacap Navigator information disclosureEPSS 0.4%CVE-2025-26013HIGHAn issue in Loggrove v.1.0 allows a remote attacker to obtain sensitive information via the read.py component.EPSS 0.4%CVE-2024-1272HIGHInformation Disclosure to Source Code in TNB Mobile Solutions' Cockpit SoftwareEPSS 0.4%CVE-2025-3403MEDIUMVivotek NVR ND8422P/NVR ND9525P/NVR ND9541P HTML Form sensitive information in sourceEPSS 0.4%CVE-2024-9596LOWInclusion of Sensitive Information in Source Code in GitLabEPSS 0.3%CVE-2025-23215CRITICALPMD Designer's release key passphrase (GPG) available on Maven Central in cleartextEPSS 0.3%CVE-2024-27257MEDIUMIBM OpenPages information disclosureEPSS 0.3%CVE-2026-45728HIGHAlgernon: Single-file mode unconditionally enables debug modeEPSS 0.3%