Weaknesses of type CWE-922

283 results

Armazenamento inseguro de informações sensíveis

É quando dados críticos (senhas, tokens, chaves criptográficas, PII) são guardados em local ou formato que qualquer pessoa com acesso ao sistema consegue ler. O risco: um atacante com acesso ao disco, memória ou arquivo de configuração rouba os dados sem esforço, comprometendo usuários e a aplicação inteira.

Example

Um app grava a senha do usuário em texto plano dentro de um arquivo .txt na raiz do projeto, ou armazena token de API em um cookie sem criptografia. Se o servidor for invadido ou o cliente roubado, as credenciais caem na mão de quem não deveria ter.

How to mitigate

Use criptografia forte (AES-256) para dados em repouso, aplique hash com salt (bcrypt, Argon2) em senhas, armazene segredos em vaults dedicados (AWS Secrets Manager, HashiCorp Vault), e nunca commita chaves ou credenciais no código. Revise regularmente o que é guardado e onde.

CVE-2021-42718MEDIUMSensitive data unnecessarily returned from authenticated APIEPSS 0.4%CVE-2024-23217LOWA privacy issue was addressed with improved handling of temporary files. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3,EPSS 0.4%CVE-2024-48353HIGHYealink Meeting Server before V26.0.0.67 allows attackers to obtain static key information from a front-end JS file and decrypt the plaintexEPSS 0.4%CVE-2024-25360MEDIUMA hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafteEPSS 0.4%CVE-2022-30361MEDIUMOvalEdge 5.2.8.0 and earlier is affected by a Sensitive Data Exposure vulnerability via a GET request to /user/getUserType. No authenticatioEPSS 0.4%CVE-2022-32867LOWThis issue was addressed with improved data protection. This issue is fixed in iOS 16, macOS Ventura 13. A user with physical access to an iEPSS 0.4%CVE-2026-33407HIGHWallos: SSRF via HTTP Proxy Environment VariableEPSS 0.4%CVE-2024-40813MEDIUMA lock screen issue was addressed with improved state management. This issue is fixed in iOS 17.6 and iPadOS 17.6, watchOS 10.6. An attackerEPSS 0.4%CVE-2020-10368LOWCertain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "SpeEPSS 0.4%CVE-2024-28808LOWAn issue was discovered in Infinera hiT 7300 5.60.50. Hidden functionality in the web interface allows a remote authenticated attacker to acEPSS 0.4%CVE-2024-23561MEDIUMHCL DevOps Deploy / HCL Launch is vulnerable to sensitive information disclosure vulnerabilityEPSS 0.4%CVE-2024-42018HIGHAn issue was discovered in Atos Eviden SMC xScale before 1.6.6. During initialization of nodes, some configuration parameters are retrieved EPSS 0.4%CVE-2023-49515MEDIUMInsecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proxiEPSS 0.4%CVE-2024-55931MEDIUMToken stored in session storageEPSS 0.4%CVE-2025-25732MEDIUMIncorrect access control in the EEPROM component of Kapsch TrafficCom RIS-9160 & RIS-9260 Roadside Units (RSUs) v3.2.0.829.23, v3.8.0.1119.4EPSS 0.4%CVE-2024-53931CRITICALThe com.glitter.caller.screen (aka iCaller, Caller Theme & Dialer) application through 1.1 for Android enables any application (with no permEPSS 0.4%CVE-2024-53932CRITICALThe com.remi.colorphone.callscreen.calltheme.callerscreen (aka Color Phone: Call Screen Theme) application through 21.1.9 for Android enableEPSS 0.4%CVE-2019-5633MEDIUMHickory Smart Lock Insecure Storage on iOSEPSS 0.4%CVE-2019-5632MEDIUMHickory Smart Lock Insecure Storage on AndroidEPSS 0.4%CVE-2019-5627LOWBlueCats Reveal iOS App Insecure StorageEPSS 0.4%