Fallos del tipo CWE-522

682 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2018-8858If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) theEPSS 1.2%CVE-2021-28171CRITICALVangene deltaFlow E-platform - Broken AuthenticationEPSS 1.2%CVE-2021-3344A privilege escalation flaw was found in OpenShift builder. During build time, credentials outside the build context are automatically mountEPSS 1.2%CVE-2017-5189MEDIUMprivate SSL key embedded in JAR file in iManagerEPSS 1.2%CVE-2020-25235A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). The password used for authentication for thEPSS 1.2%CVE-2023-29055HIGHApache Kylin: Insufficiently protected credentials in config fileEPSS 1.1%CVE-2022-46967CRITICALAn access control issue in Revenue Collection System v1.0 allows unauthenticated attackers to view the contents of /admin/DBbackup/ directorEPSS 1.1%CVE-1999-0013HIGHStolen credentials from SSH clients via ssh-agent program, allowing other local users to access remote accounts belonging to the ssh-agent uEPSS 1.1%CVE-2019-13421Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configuEPSS 1.1%CVE-2019-5648HIGHLDAP Credential Exposure in Barracuda Load Balancer ADCEPSS 1.1%CVE-2024-40710HIGHA series of related high-severity vulnerabilities, the most notable enabling remote code execution (RCE) as the service account and extractiEPSS 1.1%CVE-2021-27491Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.EPSS 1.1%CVE-2021-28813CRITICALInsufficiently Protected Credentials Vulnerability in QSW-M2116P-2T2S and QuNetSwitchEPSS 1.1%CVE-2025-4679MEDIUMA vulnerability in Synology Active Backup for Microsoft 365 allows remote authenticated attackers to obtain sensitive information via unspecEPSS 1.1%CVE-2021-1232MEDIUMCisco SD-WAN vManage Information Disclosure VulnerabilityEPSS 1.1%CVE-2020-7030MEDIUMIPO Information DisclosureEPSS 1.0%CVE-2023-35348MEDIUMActive Directory Federation Service Security Feature Bypass VulnerabilityEPSS 1.0%CVE-2021-20997HIGHWAGO: Managed Switches: Unauthorized access to password hashesEPSS 1.0%CVE-2020-5406PCF Autoscaling logs its database credentialsEPSS 1.0%CVE-2017-13998An Insufficiently Protected Credentials issue was discovered in LOYTEC LVIS-3ME versions prior to 6.2.0. The application does not sufficientEPSS 1.0%