Fallos del tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

É quando senhas, tokens ou chaves de acesso são armazenados ou transmitidos sem criptografia adequada, em texto plano ou com proteção fraca. O atacante que ganhar acesso ao código-fonte, banco de dados ou rede consegue ler as credenciais diretamente e entrar no sistema.

Ejemplo

Um desenvolvedor deixa a senha do banco de dados hardcoded em um arquivo .env versionado no Git, ou a API transmite tokens de autenticação por HTTP ao invés de HTTPS. Qualquer pessoa com acesso ao repositório ou monitorando a rede consegue roubar as credenciais.

Cómo mitigar

Use variáveis de ambiente ou gerenciadores de segredos (como HashiCorp Vault, AWS Secrets Manager); nunca versione credenciais. Sempre transmita sobre HTTPS, aplique hash com salt para senhas armazenadas, e implemente expiração e rotação de tokens e chaves.

CVE-2025-23040MEDIUMMaliciously crafted remote URLs could lead to credential leak in GitHub DesktopEPSS 0.8%CVE-2020-5400HIGHCloud Controller logs environment variables from app manifestsEPSS 0.8%CVE-2023-41677HIGHA insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 EPSS 0.8%CVE-2021-41297HIGHECOA BAS controller - Insufficiently Protected Credentials-1EPSS 0.7%CVE-2022-30296HIGHInsufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated userEPSS 0.7%CVE-2020-8259Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.EPSS 0.7%CVE-2019-14840HIGHA flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentialsEPSS 0.7%CVE-2026-6253MEDIUMproxy credentials leak over redirect-to proxyEPSS 0.7%CVE-2020-15791MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-4EPSS 0.7%CVE-2024-29992MEDIUMAzure Identity Library for .NET Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43419MEDIUMJenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viEPSS 0.7%CVE-2022-23538MEDIUMUser credentials leaked to third-party service via HTTP redirect in scs-library-clientEPSS 0.7%CVE-2022-28291MEDIUMInsufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “neEPSS 0.7%CVE-2023-25413HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.EPSS 0.7%CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonaEPSS 0.7%CVE-2022-45384MEDIUMJenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the JenkinEPSS 0.7%CVE-2024-57395CRITICALPassword Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrarEPSS 0.7%CVE-2022-1766Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add EPSS 0.7%CVE-2022-45392MEDIUMJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the JenEPSS 0.7%CVE-2026-54617CRITICALGravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandlerEPSS 0.7%