Fallos del tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia dados críticos (senhas, tokens, informações pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na mesma rede ou posicionado no caminho do tráfego consegue ler esses dados diretamente, comprometendo confidencialidade.

Ejemplo

Um aplicativo mobile que envia credenciais de login via HTTP simples em vez de HTTPS, ou um sistema legado que transmite números de cartão de crédito em texto plano pela rede corporativa. Qualquer um fazendo sniffing de pacotes consegue capturar essas informações.

Cómo mitigar

Use HTTPS/TLS para toda comunicação que envolva dados sensíveis, implemente verificação de certificados válidos no cliente, e nunca transmita senhas ou tokens em parâmetros GET — prefira POST com corpo criptografado. Em APIs, aplique autenticação com tokens seguros e considere criptografia adicional end-to-end para dados ultra-críticos.

CVE-2025-57727MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote referenceEPSS 0.2%CVE-2025-44612MEDIUMTinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device creEPSS 0.2%CVE-2024-8059MEDIUMIPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.EPSS 0.2%CVE-2019-6540MEDIUMMedtronic Conexus Radio Frequency Telemetry Protocol Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-44251HIGHEcovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.EPSS 0.2%CVE-2026-27752HIGHSODOLA SL902-SWTGW124AS <= 200.1.20 Cleartext Credential TransmissionEPSS 0.2%CVE-2023-24440MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins cEPSS 0.2%CVE-2025-13489MEDIUMIBM DevOps Deploy is susceptible to a Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2025-12508HIGHUnencrypted communication to Active Directory servicesEPSS 0.2%CVE-2026-40431MEDIUMSenseLive X3050 Cleartext transmission of sensitive informationEPSS 0.2%CVE-2026-81836MEDIUMRooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmissionEPSS 0.2%CVE-2026-33569MEDIUMAnviz Products Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-64648MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-43625HIGHCodexBar < 0.32.0 Session Cookie Exposure via HTTP RedirectEPSS 0.2%CVE-2025-13490MEDIUMIBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentialityEPSS 0.2%CVE-2025-70048HIGHAn issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.2%CVE-2026-50200HIGHSteeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsEPSS 0.2%CVE-2025-13718LOWIBM Sterling Partner Engagement Manager Information DisclosureEPSS 0.2%CVE-2025-52490HIGHAn issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passEPSS 0.2%