Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2026-33575HIGHOpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup CodesEPSS 0.2%CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.2%CVE-2019-10139MEDIUMDuring HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleEPSS 0.2%CVE-2026-0393MEDIUMCODESYS Visualization - Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-53657MEDIUMJenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed oEPSS 0.2%CVE-2025-53660MEDIUMJenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, incEPSS 0.2%CVE-2026-27777MEDIUMMobiliti e-mobi.hu Insufficiently Protected CredentialsEPSS 0.2%CVE-2026-54660HIGHswagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`EPSS 0.2%CVE-2026-76846HIGHGrav before 2.0.16 Information Disclosure via Twig SandboxEPSS 0.2%CVE-2026-72793CRITICALSiYuan before v3.7.4 Information Disclosure via /api/system/getConfEPSS 0.2%CVE-2026-72801HIGHSiYuan before v3.7.4 Information Disclosure via Encryption Key MaterialEPSS 0.2%CVE-2025-53661MEDIUMJenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing EPSS 0.2%CVE-2026-71511HIGHDolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member EndpointsEPSS 0.2%CVE-2026-14564CRITICALSensitive Data Exposure in Innotim Software's Logsign SIEMEPSS 0.2%CVE-2026-82070HIGHInsufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceEPSS 0.2%CVE-2022-33954MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.2%CVE-2023-50436MEDIUMAn issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The eEPSS 0.2%CVE-2025-69271LOWSpectrum basic authentication in useEPSS 0.2%CVE-2026-28961MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attackEPSS 0.2%CVE-2021-22781—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%