Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.3%CVE-2024-47161MEDIUMIn JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST APIEPSS 0.3%CVE-2022-36307—The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 softwaEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.3%CVE-2026-1433MEDIUMuniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information DisclosureEPSS 0.3%CVE-2026-14019MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a EPSS 0.3%CVE-2020-16097HIGHOn controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed EPSS 0.3%CVE-2026-27316LOWA insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbEPSS 0.3%CVE-2026-34262MEDIUMInformation Disclosure Vulnerability in SAP HANA Cockpit and HANA Database ExplorerEPSS 0.3%CVE-2021-47726HIGHNuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration BackupEPSS 0.3%CVE-2022-43442MEDIUMPlaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow an attacker to obtaiEPSS 0.3%CVE-2026-28204MEDIUMCTEK Chargeportal Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-36096CRITICALAIX Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-14148MEDIUMIBM DevOps Deploy is susceptible to a Insufficiently Protected Credentials vulnerabilityEPSS 0.3%CVE-2026-20791MEDIUMChargemap chargemap.com Insufficiently Protected CredentialsEPSS 0.3%CVE-2024-56354MEDIUMIn JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permissionEPSS 0.3%CVE-2026-82247HIGHgitoxide before 0.37.1 HTTP Basic credential leak via URL parsingEPSS 0.3%CVE-2026-22890MEDIUMEV2GO ev2go.io Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.3%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.3%