Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2024-46480HIGHAn NTLM hash leak in Venki Supravizio BPM up to 18.0.1 allows authenticated attackers with Application Administrator access to escalate privEPSS 0.5%CVE-2023-32280MEDIUMInsufficiently protected credentials in some Intel(R) Server Product OpenBMC firmware before versions egs-1.05 may allow an unauthenticated EPSS 0.5%CVE-2023-1574MEDIUMInformation disclosure in the user creation feature of a MSSQL data source in Devolutions Remote Desktop Manager 2023.1.9 and below on WindoEPSS 0.5%CVE-2025-27192LOWAdobe Commerce | Insufficiently Protected Credentials (CWE-522)EPSS 0.5%CVE-2026-82434CRITICALApache Storm Nimbus, Apache Storm Client: Disclosure of the Topology ZooKeeper Credential to Read-Only Users and to LogsEPSS 0.5%CVE-2025-34196CRITICALVasion Print (formerly PrinterLogic) Hardcoded PrinterLogic CA Private Key and Hardcoded PasswordEPSS 0.5%CVE-2023-25531HIGHNVIDIA DGX H100 BMC contains a vulnerability in IPMI, where an attacker may cause insufficient protection of credentials. A successful exploEPSS 0.5%CVE-2024-5176CRITICALVulnerability in Welch Allyn Configuration Tool SoftwareEPSS 0.5%CVE-2026-64918MEDIUMMicrosoft Office Spoofing VulnerabilityEPSS 0.5%CVE-2023-29168LOWPTC Vuforia Studio Insufficiently Protected CredentialsEPSS 0.5%CVE-2023-31187MEDIUMAvaya IX Workforce Engagement - CWE-522: Insufficiently Protected CredentialsEPSS 0.5%CVE-2026-59891CRITICALCredential confusion in  @sigstore/oci  can leak registry credentials to an attacker-controlled registryEPSS 0.5%CVE-2026-32633CRITICALGlances's Browser API Exposes Reusable Downstream Credentials via `/api/4/serverslist`EPSS 0.5%CVE-2022-41564MEDIUMTIBCO Operational Intelligence Hawk Redtail Credential Exposure VulnerabilityEPSS 0.5%CVE-2024-41771HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2019-17082CRITICALInsufficiently Protected Credentials vulnerability in OpenText™ AccuRev allows Authentication Bypass. When installed on a Linux or Solaris sEPSS 0.5%CVE-2024-41770HIGHIBM Engineering Requirements Management DOORS Next information disclosureEPSS 0.5%CVE-2025-52549CRITICALPredictable root linux password generationEPSS 0.5%CVE-2022-26341HIGHInsufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R)EPSS 0.5%CVE-2025-62157HIGHArgo Workflows exposes artifact repository credentials in workflow-controller logsEPSS 0.5%