Fallos del tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2023-6259HIGHLocal Access to Sensitive Data in Brivo ACS100 and ACS300 EPSS 0.2%CVE-2024-46341HIGHTP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker exEPSS 0.2%CVE-2025-53669MEDIUMJenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential fEPSS 0.2%CVE-2026-82255HIGHgitoxide 0.25.4 HTTP Credential Leak via RedirectEPSS 0.2%CVE-2025-37728MEDIUMKibana Insufficiently Protected Credentials in the CrowdStrike ConnectorEPSS 0.2%CVE-2026-11921CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2026-8862HIGHVulnerabilities exists in IBM Netezza SoftwareEPSS 0.2%CVE-2026-35467HIGHPrivate Key stored as extractable in browser IndexeDBEPSS 0.2%CVE-2026-71260MEDIUMESPHome web_server Plaintext Password Disclosure via JSON "value" FieldEPSS 0.2%CVE-2026-0715HIGHMoxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An EPSS 0.2%CVE-2025-42897MEDIUMInformation Disclosure vulnerability in SAP Business One (SLD)EPSS 0.2%CVE-2026-6345MEDIUMPrevent password disclosure and force reset during Slack importEPSS 0.2%CVE-2022-38465CRITICALA vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP EPSS 0.2%CVE-2020-10710—A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This EPSS 0.2%CVE-2026-6446MEDIUMMy Social Feeds <= 1.0.4 - Missing Authorization to Unauthenticated Sensitive Information Exposure via 'ttp_get_accounts' AJAX ActionEPSS 0.2%CVE-2026-71577MEDIUMMulticluster-global-hub: multicluster-global-hub: spec-topic read acl leaks bootstrap kubeconfigs to all managed hubs during migrationEPSS 0.2%CVE-2016-15014LOWCESNET theme-cesnet resetpassword.php insufficiently protected credentialsEPSS 0.2%CVE-2026-0289LOWPrisma Browser: Inappropriate Implementation in Account ProtectionEPSS 0.2%CVE-2021-40503—An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficEPSS 0.2%CVE-2021-34733MEDIUMCisco Prime Infrastructure and Cisco Evolved Programmable Network Manager Information Disclosure VulnerabilityEPSS 0.2%