Fallos del tipo CWE-311

312 resultados

Ausência de criptografia para dados sensíveis

A aplicação processa ou armazena dados sensíveis (senhas, tokens, dados financeiros, PII) sem aplicar criptografia. Isso expõe as informações a quem tiver acesso ao meio de transmissão ou armazenamento, permitindo roubo ou vazamento direto.

Ejemplo

Um servidor que salva tokens de autenticação em um arquivo de log em texto plano, ou uma API que trafega CPF e dados bancários via HTTP simples em vez de HTTPS. Um atacante monitora a rede ou acessa o servidor e recupera os dados.

Cómo mitigar

Sempre use HTTPS/TLS para transmissão de dados sensíveis, criptografe dados em repouso usando algoritmos reconhecidos (AES-256), e aplique criptografia end-to-end onde possível. Nunca deixe senhas ou tokens em logs ou cache sem proteção.

CVE-2016-10650ntfserver is a Network Testing Framework Server. ntfserver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks.EPSS 2.0%CVE-2016-10636grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITMEPSS 2.0%CVE-2016-10644slimerjs-edge is a npm wrapper for installing the bleeding edge version of slimerjs. slimerjs-edge downloads binary resources over HTTP, whiEPSS 2.0%CVE-2016-10637haxe-dev is a cross-platform toolkit. haxe-dev downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be pEPSS 2.0%CVE-2016-10634scala-standalone-bin is a Binary wrapper for ScalaJS. scala-standalone-bin downloads binary resources over HTTP, which leaves it vulnerable EPSS 2.0%CVE-2016-10640node-thulac is a node binding for thulac. node-thulac downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It mEPSS 2.0%CVE-2016-10698mystem-fix is a node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem-fix downloads binary resources over HTTP, which leavEPSS 2.0%CVE-2016-10558aerospike is an Aerospike add-on module for Node.js. aerospike versions below 2.4.2 download binary resources over HTTP, which leaves the moEPSS 2.0%CVE-2016-10676rs-brightcove is a wrapper around brightcove's web api rs-brightcove downloads source file resources over HTTP, which leaves it vulnerable tEPSS 2.0%CVE-2016-10648marionette-socket-host is a marionette-js-runner host for sending actions over a socket. marionette-socket-host downloads binary resources oEPSS 2.0%CVE-2016-10605dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerablEPSS 2.0%CVE-2016-10611strider-sauce is Sauce Labs / Selenium support for Strider. strider-sauce downloads zipped resources over HTTP, which leaves it vulnerable tEPSS 2.0%CVE-2016-10677google-closure-tools-latest is a Node.js module wrapper for downloading the latest version of the Google Closure tools google-closure-tools-EPSS 2.0%CVE-2016-10627scala-bin is a binary wrapper for Scala. scala-bin downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may EPSS 2.0%CVE-2016-10586macaca-chromedriver is a Node.js wrapper for the selenium chromedriver. macaca-chromedriver before 1.0.29 downloads binary resources over HTEPSS 2.0%CVE-2016-10589selenium-binaries downloads Selenium related binaries for your OS. selenium-binaries downloads binary resources over HTTP, which leaves it vEPSS 2.0%CVE-2016-10695The npm-test-sqlite3-trunk module provides asynchronous, non-blocking SQLite3 bindings. npm-test-sqlite3-trunk downloads binary resources ovEPSS 2.0%CVE-2016-10687windows-selenium-chromedriver is a module that downloads the Selenium Jar file. windows-selenium-chromedriver downloads binary resources oveEPSS 2.0%CVE-2016-10569embedza is a module to create HTML snippets/embeds from URLs using info from oEmbed, Open Graph, meta tags. embedza versions below 1.2.4 dowEPSS 2.0%CVE-2016-10621fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable EPSS 2.0%