Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2024-34887MEDIUMInsufficiently protected credentials in AD/LDAP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send AD/LDAEPSS 0.3%CVE-2024-34882MEDIUMInsufficiently protected credentials in SMTP server settings in 1C-Bitrix Bitrix24 23.300.100 allows remote administrators to send SMTP accoEPSS 0.3%CVE-2024-27109HIGHInsufficiently protected credentials in GE HealthCare EchoPAC productsEPSS 0.3%CVE-2026-15977HIGHCVE-2026-15977EPSS 0.3%CVE-2024-47271MEDIUMInsufficiently protected credentials vulnerability in IPSpeaker component in Synology Surveillance Station before 9.2.2-11575 and 9.2.2-9575EPSS 0.3%CVE-2024-49364HIGHtiny-secp256k1 vulnerable to private key extraction when signing a malicious JSON-stringifyable message in bundled environmentEPSS 0.3%CVE-2026-92759HIGHSecObserve before 1.59.1 Information Disclosure via API ConfigurationEPSS 0.3%CVE-2026-55431HIGHCoder's session token leaked to arbitrary hosts via `coder open app` for external workspace appsEPSS 0.3%CVE-2025-64998HIGHSession hijacking via exposed session signing secret in distributed Checkmk setupsEPSS 0.3%CVE-2024-21815CRITICAL Insufficiently protected credentials (CWE-522) for third party DVR integrations to the Command Centre Server are accessible to authenticateEPSS 0.3%CVE-2025-13164MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-13163MEDIUMDigiwin|EasyFlow GP - Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-85717MEDIUMAsyncHttpClient: Client-wide realm credentials re-sent to a cross-origin redirect targetEPSS 0.3%CVE-2025-0497HIGHRockwell Automation FactoryTalk® AssetCentre Data Exposure VulnerabilityEPSS 0.3%CVE-2017-2665MEDIUMThe skyring-setup command creates random password for mongodb skyring database but it writes password in plain text to /etc/skyring/skyring.EPSS 0.3%CVE-2026-45091CRITICALsealed-env: TOTP secret embedded in unseal token payload (enterprise mode)EPSS 0.3%CVE-2020-8152—Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decryEPSS 0.3%CVE-2023-50311LOWIBM CICS Transaction Gateway for Multiplatforms information disclosureEPSS 0.3%CVE-2025-35941MEDIUMmySCADA PRO Manager Password DisclosureEPSS 0.3%CVE-2025-9521LOWPassword Confirmation Bypass in Omada ControllerEPSS 0.3%