Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-59209HIGHn8n: Shared Credential Header Leak via HTTP Request Pagination ExpressionEPSS 0.4%CVE-2026-21670HIGHA vulnerability allowing a low-privileged user to extract saved SSH credentials.EPSS 0.4%CVE-2026-54618CRITICALObsidian Web MCP: Unauthenticated vault access: /oauth/authorize auto-approves without authenticating the userEPSS 0.4%CVE-2024-31800MEDIUMAuthentication Bypass in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to gain a privileged command shell EPSS 0.4%CVE-2023-50310MEDIUMIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.4%CVE-2019-10224MEDIUMA flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may diEPSS 0.4%CVE-2026-62684LOWFile Browser: Share API exposes the password hash and bypass tokenEPSS 0.4%CVE-2026-39462CRITICALSenseLive X3050 Insufficiently Protected CredentialsEPSS 0.4%CVE-2024-49396HIGHInsufficiently Protected Credentials in Elvaco M-Bus Metering Gateway CMe3100EPSS 0.4%CVE-2025-15617HIGHWazuh GitHub Actions Workflow Exposure of Sensitive CredentialsEPSS 0.4%CVE-2019-10210MEDIUMPostgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotectedEPSS 0.4%CVE-2026-81861MEDIUMCWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information and unauthorized accEPSS 0.4%CVE-2023-49233HIGHInsufficient access checks in Visual Planning Admin Center 8 before v.1 Build 240207 allow attackers in possession of a non-administrative VEPSS 0.4%CVE-2026-61516CRITICALNetis NX10 Credential Disclosure via sysinfo Diagnostic EndpointEPSS 0.4%CVE-2025-0498HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.4%CVE-2019-10981In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an authenticated local userEPSS 0.4%CVE-2024-12799CRITICALInsufficiently Protected CredentialsEPSS 0.4%CVE-2025-40838MEDIUMEricsson Indoor Connect 8855 - Insufficiently Protected Credentials VulnerabilityEPSS 0.4%CVE-2025-7386MEDIUMInformation exposure vulnerability in Hitachi Storage NavigatorEPSS 0.4%CVE-2024-34883MEDIUMInsufficiently protected credentials in DAV server settings in 1C-Bitrix Bitrix24 23.300.100 allow remote administrators to read proxy-serveEPSS 0.4%