Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2024-38453HIGHThe Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-EPSS 0.4%CVE-2025-26492HIGHIn JetBrains TeamCity before 2024.12.2 improper Kubernetes connection settings could expose sensitive resourcesEPSS 0.4%CVE-2025-30183HIGHCyberData 011209 SIP Emergency Intercom Insufficiently Protected CredentialsEPSS 0.4%CVE-2021-36204HIGHInsufficiently Protected Credentials in Metasys EPSS 0.4%CVE-2026-84179MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology PageEPSS 0.4%CVE-2026-82433MEDIUMApache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Daemon Configuration via Nimbus and the UIEPSS 0.4%CVE-2024-42457HIGHA vulnerability in Veeam Backup & Replication allows users with certain operator roles to expose saved credentials by leveraging a combinatiEPSS 0.4%CVE-2024-4536MEDIUMEclipse EDC: OAuth2 Credential Exfiltration VulnerabilityEPSS 0.4%CVE-2023-23466MEDIUMMedia CP Media Control Panel – insufficiently protected credential changeEPSS 0.4%CVE-2025-55739MEDIUMapi: Shared OAuth Signing Key Between Different InstancesEPSS 0.4%CVE-2023-1518HIGHCP Plus KVMS Pro versions 2.01.0.T.190521 and prior are vulnerable to sensitive credentials being leaked because they are insufficiently pEPSS 0.4%CVE-2020-37097HIGHEdimax EW-7438RPn 1.13 - Information Disclosure (WiFi Password)EPSS 0.4%CVE-2026-61802MEDIUMWazuh discloses cleartext cluster key to low-privilege API users via GET /cluster/local/configEPSS 0.4%CVE-2026-15806MEDIUM`HTTPPasswordMgr` can send saved HTTPS credentials via HTTP because of incorrect scheme matchingEPSS 0.4%CVE-2026-9650HIGHCWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when uEPSS 0.4%CVE-2026-30796MEDIUMRustDesk Client Transmits Preset Address Book Password Verbatim in Heartbeat SyncEPSS 0.4%CVE-2021-43767Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'truEPSS 0.4%CVE-2022-2967MEDIUMProsys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credEPSS 0.4%CVE-2025-38739HIGHDell Digital Delivery, versions prior to 5.6.1.0, contains an Insufficiently Protected Credentials vulnerability. A remote unauthenticated aEPSS 0.4%CVE-2024-22266MEDIUMVMware Avi Load Balancer updates address multiple vulnerabilitiesEPSS 0.4%