Weaknesses of type CWE-922

283 results

Armazenamento inseguro de informações sensíveis

É quando dados críticos (senhas, tokens, chaves criptográficas, PII) são guardados em local ou formato que qualquer pessoa com acesso ao sistema consegue ler. O risco: um atacante com acesso ao disco, memória ou arquivo de configuração rouba os dados sem esforço, comprometendo usuários e a aplicação inteira.

Example

Um app grava a senha do usuário em texto plano dentro de um arquivo .txt na raiz do projeto, ou armazena token de API em um cookie sem criptografia. Se o servidor for invadido ou o cliente roubado, as credenciais caem na mão de quem não deveria ter.

How to mitigate

Use criptografia forte (AES-256) para dados em repouso, aplique hash com salt (bcrypt, Argon2) em senhas, armazene segredos em vaults dedicados (AWS Secrets Manager, HashiCorp Vault), e nunca commita chaves ou credenciais no código. Revise regularmente o que é guardado e onde.

CVE-2023-32191CRITICALrke's credentials are stored in the RKE1 Cluster state ConfigMapEPSS 0.7%CVE-2024-26559MEDIUMAn issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.EPSS 0.7%CVE-2022-1257MEDIUMImproper Verification of Cryptographic Signature by McAfee AgentEPSS 0.6%CVE-2024-57436HIGHRuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allEPSS 0.6%CVE-2023-6565MEDIUMInfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information ExposureEPSS 0.6%CVE-2024-44175HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be aEPSS 0.6%CVE-2023-45182HIGHIBM i Access Client Solutions information disclosureEPSS 0.6%CVE-2022-32833MEDIUMAn issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue EPSS 0.6%CVE-2024-27789MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 1EPSS 0.6%CVE-2022-20939MEDIUMCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-57546HIGHAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.6%CVE-2024-28069HIGHA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to EPSS 0.6%CVE-2022-2815MEDIUMInsecure Storage of Sensitive Information in publify/publifyEPSS 0.6%CVE-2024-5598HIGHAdvanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory ListingEPSS 0.6%CVE-2023-42913HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to oEPSS 0.5%CVE-2023-37879MEDIUMExposed Session Variable in Wing FTP Server <= 7.2.0EPSS 0.5%CVE-2023-45859HIGHIn Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client EPSS 0.5%CVE-2024-5599HIGHFileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory ListingEPSS 0.5%CVE-2023-22687LOWWordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-22808HIGHAn issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the comEPSS 0.5%