Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-20733MEDIUMCloudCharge cloudcharge.se Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-76839HIGHGrav before 2.0.16 Information Disclosure via offsetGetEPSS 0.3%CVE-2019-10205MEDIUMA flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red EPSS 0.3%CVE-2024-28981HIGHHitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2023-24619MEDIUMRedpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and SecretEPSS 0.3%CVE-2026-8368MEDIUMLWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirectsEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%CVE-2024-51240HIGHAn issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API,EPSS 0.3%CVE-2025-52545HIGHPrivilege escalation in the application servicesEPSS 0.3%CVE-2025-53743MEDIUMJenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the EPSS 0.3%CVE-2026-15657MEDIUMforeUP customer REST API allows authenticated users to read cleartext payment-processor merchant credentialsEPSS 0.3%CVE-2026-86175HIGHNetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIsEPSS 0.3%CVE-2024-47142MEDIUMAIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently prEPSS 0.3%CVE-2026-86726HIGHAVideo through 29.0 Information Disclosure via restreamsActive.json.phpEPSS 0.3%CVE-2025-53008MEDIUMGLPI's MailCollector Receiver is vulnerable to credential exfiltrationEPSS 0.3%CVE-2023-41926HIGHInsufficiently protected credentials in Kiloview P1/P2 devicesEPSS 0.3%CVE-2020-7307MEDIUMDLP for Mac - Unprotected Storage of CredentialsEPSS 0.3%CVE-2026-41506MEDIUMgo-git Credential leak via cross-host redirect in smart HTTP transportEPSS 0.3%CVE-2019-3938—Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the fEPSS 0.3%