Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-76854HIGHNetcore NR255-V 1.5.130703 Sensitive Information Disclosure via l7_web_auth_user_show.cgiEPSS 0.5%CVE-2025-54428CRITICALRevelaCode exposes Sensitive MongoDB Atlas URI in .env (potential credential leak)EPSS 0.5%CVE-2022-46155HIGHAirtable.js credentials exposed in browser buildsEPSS 0.5%CVE-2025-27231MEDIUMLDAP 'Bind password' field value can be leaked by a Zabbix Super AdminEPSS 0.5%CVE-2025-34139HIGHSitecore XM/XP/XC and Managed Cloud 8.0 - 10.4 Arbitrary File ReadEPSS 0.5%CVE-2023-23463MEDIUM Sunell DVR – Insufficiently Protected CredentialsEPSS 0.5%CVE-2025-54876MEDIUMJans CLI stores plaintext passwords in the local cli_cmd.log fileEPSS 0.5%CVE-2026-56783HIGHParseable < 2.9.2 - Cleartext Credential Exposure in Notification Target APIEPSS 0.5%CVE-2023-48010CRITICALSTMicroelectronics SPC58 is vulnerable to Missing Protection Mechanism for Alternate Hardware Interface. Code running as Supervisor on the SEPSS 0.5%CVE-2022-27560MEDIUMAn insufficiently protected credential vulnerability affects HCL VersionVault ExpressEPSS 0.5%CVE-2026-3783MEDIUMtoken leak with redirect and netrcEPSS 0.5%CVE-2026-27167NONEGradio: Mocked OAuth Login Exposes Server Credentials and Uses Hardcoded Session SecretEPSS 0.5%CVE-2025-2772MEDIUMBEC Technologies Multiple Routers Insufficiently Protected Credentials Information Disclosure VulnerabilityEPSS 0.5%CVE-2020-36968HIGHM/Monit 3.7.4 - Password DisclosureEPSS 0.4%CVE-2026-8926CRITICALpassword leak with netrc and user in URLEPSS 0.4%CVE-2026-11827MEDIUMInsufficiently Protected Credentials in GitLabEPSS 0.4%CVE-2023-43905HIGHIncorrect access control in writercms v1.1.0 allows attackers to directly obtain backend account passwords via unspecified vectors.EPSS 0.4%CVE-2024-38505MEDIUMIn JetBrains YouTrack before 2024.2.34646 user access token was sent to the third-party siteEPSS 0.4%CVE-2022-27544MEDIUMHCL BigFix Web Reports authorized users may see sensitive information in clear textEPSS 0.4%CVE-2026-44938HIGHFleet has PSS Bypass through addLabelsFromOptions in Fleet AgentEPSS 0.4%