Fallos del tipo CWE-311
312 resultadosAusência de criptografia para dados sensíveis
A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.
Ejemplo
Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.
Cómo mitigar
Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.
CVE-2025-29314HIGHInsecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to EPSS 0.2%CVE-2025-53678MEDIUMJenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins contEPSS 0.2%CVE-2025-53676MEDIUMJenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controlleEPSS 0.2%CVE-2025-53673MEDIUMJenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration filEPSS 0.2%CVE-2020-7567HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attEPSS 0.2%CVE-2024-23444MEDIUMElasticsearch elasticsearch-certutil csr fails to encrypt private keyEPSS 0.2%CVE-2024-25631MEDIUMUnencrypted traffic between pods when using Wireguard and an external kvstoreEPSS 0.2%CVE-2026-81688HIGHopenssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256EPSS 0.2%CVE-2025-53653MEDIUMJenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the JenkinsEPSS 0.2%CVE-2023-30561MEDIUMLack of Cryptographic Security of IUI Bus EPSS 0.2%CVE-2024-40620MEDIUMRockwell Automation Pavilion8® Unencrypted Data Vulnerability via HTTP protocolEPSS 0.2%CVE-2024-25630MEDIUMCilium has unencrypted ingress/health traffic when using Wireguard transparent encryptionEPSS 0.2%CVE-2025-64143MEDIUMJenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controllEPSS 0.2%CVE-2026-53442MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job confEPSS 0.2%CVE-2023-28045MEDIUM
Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could EPSS 0.2%CVE-2023-6339CRITICALGoogle Nest WiFi Pro root code-execution & user-data compromiseEPSS 0.2%CVE-2018-8864—In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vuEPSS 0.2%CVE-2024-47871HIGHInsecure communication between the FRP client and server in GradioEPSS 0.2%CVE-2020-9062—Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2024-28250MEDIUMCilium has possible unencrypted traffic between nodes when using WireGuard and L7 policiesEPSS 0.2%