Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2019-11820MEDIUMInformation exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentiaEPSS 0.3%CVE-2021-47741HIGHZBL EPON ONU Broadband Router V100R001 Privilege Escalation via Configuration EndpointEPSS 0.3%CVE-2021-32039MEDIUMMongoDB Extension for VS Code may unexpectedly store credentials locally in clear textEPSS 0.3%CVE-2024-39878MEDIUMIn JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App ConnectionEPSS 0.3%CVE-2026-92256HIGHNetcore NR255-V 1.5.130703 IPsec PSK and RSA Key Disclosure via l2tpd_config_show.cgi Read HandlersEPSS 0.3%CVE-2026-25774MEDIUMEV Energy ev.energy Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-76871HIGHNetcore NR255-V 1.5.130703 Sensitive Information Disclosure via VPN Read HandlersEPSS 0.3%CVE-2024-47109MEDIUMIBM Sterling File Gateway information disclosureEPSS 0.3%CVE-2024-11856LOWHPE IceWall Products, Remote Unauthorized Data ModificationEPSS 0.3%CVE-2026-55854MEDIUMMariaDB Connector/Node.js: Cleartext Transmission of Sensitive Information and Insufficiently Protected Credentials in mariadbEPSS 0.3%CVE-2026-22878MEDIUMMobility46 mobility46.se Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-29128HIGHIDC SFX2100 Satellite Receiver bgpd/ospfd/ripd/zebra Config Credential Disclosure via World-Readable FilesEPSS 0.3%CVE-2025-61776MEDIUMDependency-Track possibly discloses private NuGet repository credentials to api.nuget.orgEPSS 0.3%CVE-2026-53586MEDIUMlibgit2: HTTP transport can leak credentials to an offsite redirect targetEPSS 0.3%CVE-2026-91982MEDIUMVikunja before 2.6.0 TOTP Secret Disclosure via APIEPSS 0.3%CVE-2026-23922LOWEmail media OAuth secret leak to Super AdminEPSS 0.3%CVE-2025-42933HIGHInsecure Storage of Sensitive Information in SAP Business One (SLD)EPSS 0.3%CVE-2026-46511HIGHHAXcms: Mass Token Exfiltration and Cross-Tenant HijackEPSS 0.3%CVE-2025-53667MEDIUMJenkins Dead Man's Snitch Plugin 0.1 does not mask Dead Man's Snitch tokens displayed on the job configuration form, increasing the potentiaEPSS 0.3%CVE-2026-20733MEDIUMCloudCharge cloudcharge.se Insufficiently Protected CredentialsEPSS 0.3%