Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2020-5263MEDIUMInformation disclosure through error objectEPSS 0.9%CVE-2017-0925Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration APEPSS 0.9%CVE-2023-33263HIGHIn WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE:EPSS 0.9%CVE-2022-4612MEDIUMClick Studios Passwordstate insufficiently protected credentialsEPSS 0.9%CVE-2014-1423MEDIUMOnline Accounts Signon daemon gives out all oauth tokens to any appEPSS 0.8%CVE-2026-48295HIGHCAI Content Credentials | Insufficiently Protected Credentials (CWE-522)EPSS 0.8%CVE-2018-16153HIGHAn issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts tEPSS 0.8%CVE-2021-27495Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.EPSS 0.8%CVE-2021-22640HIGHOvarro TBox Insufficiently Protected CredentialsEPSS 0.8%CVE-2022-41255MEDIUMJenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it canEPSS 0.8%CVE-2022-39168MEDIUMIBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.EPSS 0.8%CVE-2022-1666MEDIUMSecheron SEPCOS Control and Protection RelayEPSS 0.8%CVE-2024-0368HIGHHustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API KeysEPSS 0.8%CVE-2026-23658HIGHAzure DevOps: msazure Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-22998HIGHProtecting AWS credentials stored in plaintext on My Cloud HomeEPSS 0.8%CVE-2023-25407HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.EPSS 0.8%CVE-2021-3513A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wroEPSS 0.8%CVE-2022-41575HIGHA credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to EPSS 0.8%CVE-2024-7813MEDIUMSourceCodester Prison Management System Profile Image insufficiently protected credentialsEPSS 0.8%CVE-2021-36783CRITICALRancher: Failure to properly sanitize credentials in cluster template answersEPSS 0.8%