Weaknesses of type CWE-922

283 results

Armazenamento inseguro de informações sensíveis

É quando dados críticos (senhas, tokens, chaves criptográficas, PII) são guardados em local ou formato que qualquer pessoa com acesso ao sistema consegue ler. O risco: um atacante com acesso ao disco, memória ou arquivo de configuração rouba os dados sem esforço, comprometendo usuários e a aplicação inteira.

Example

Um app grava a senha do usuário em texto plano dentro de um arquivo .txt na raiz do projeto, ou armazena token de API em um cookie sem criptografia. Se o servidor for invadido ou o cliente roubado, as credenciais caem na mão de quem não deveria ter.

How to mitigate

Use criptografia forte (AES-256) para dados em repouso, aplique hash com salt (bcrypt, Argon2) em senhas, armazene segredos em vaults dedicados (AWS Secrets Manager, HashiCorp Vault), e nunca commita chaves ou credenciais no código. Revise regularmente o que é guardado e onde.

CVE-2025-53507HIGHMultiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration inEPSS 0.3%CVE-2024-31404MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to theEPSS 0.3%CVE-2026-5666MEDIUMcode-projects Online FIR System SQL Database Backup File complaints.sql sensitive informationEPSS 0.3%CVE-2025-28171MEDIUMAn issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cEPSS 0.3%CVE-2024-29953MEDIUMEncoded session passwords on session storage for Virtual Fabric platformsEPSS 0.3%CVE-2023-23522MEDIUMA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.2.1. An app may be able to EPSS 0.3%CVE-2024-38312MEDIUMWhen browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed EPSS 0.3%CVE-2026-40868HIGHkyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount tokenEPSS 0.3%CVE-2024-54485MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An aEPSS 0.3%CVE-2024-49201MEDIUMKeyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information coulEPSS 0.3%CVE-2024-31400MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintenEPSS 0.3%CVE-2024-29120MEDIUMApache StreamPark: Information leakage vulnerabilityEPSS 0.3%CVE-2025-11644LOWTomofun Furbo 360/Furbo Mini UART sensitive informationEPSS 0.3%CVE-2025-70963HIGHGophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly insEPSS 0.3%CVE-2026-46511HIGHHAXcms: Mass Token Exfiltration and Cross-Tenant HijackEPSS 0.3%CVE-2024-23229MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, EPSS 0.3%CVE-2024-54477MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app mEPSS 0.3%CVE-2025-24117MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, mEPSS 0.3%CVE-2024-42677MEDIUMAn issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nEPSS 0.3%CVE-2024-36788MEDIUMNetgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly interceEPSS 0.3%