Fallos del tipo CWE-549
16 resultadosCampo de senha não mascarado
Ocorre quando um campo de entrada de senha exibe o texto digitado em claro na tela, em vez de mascarar com asteriscos ou pontos. Isso expõe a senha a espiadelas sobre o ombro, câmeras de segurança ou capturas de tela.
Ejemplo
Um formulário de login web onde você digita a senha e ela aparece visível no campo de entrada, ou um aplicativo mobile que não oculta caracteres de senha durante a digitação, permitindo que qualquer pessoa próxima leia a credencial.
Cómo mitigar
Configure atributos HTML corretos (type='password' em vez de type='text'), implemente mascaramento no lado do cliente com componentes de UI apropriados, e valide em testes de segurança que campos sensíveis nunca exibem texto plano durante entrada do usuário.
CVE-2022-20914MEDIUMCisco Identity Services Engine Sensitive Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-10122MEDIUMTopdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field maskingEPSS 0.5%CVE-2023-49106MEDIUMMissing Password Field Masking Vulnerability in Hitachi Device ManagerEPSS 0.4%CVE-2022-1342—A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching EPSS 0.4%CVE-2023-2062MEDIUMInformation Disclosure vulnerability in EtherNet/IP Configuration toolsEPSS 0.3%CVE-2025-42904MEDIUMInformation Disclosure vulnerability in Application Server ABAPEPSS 0.3%CVE-2025-13175MEDIUMInsecure Password Storage in Y Soft SafeQ 6EPSS 0.3%CVE-2023-1763MEDIUMCanon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1EPSS 0.3%CVE-2025-31727MEDIUMJenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controEPSS 0.3%CVE-2025-31728MEDIUMJenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasinEPSS 0.3%CVE-2025-4526MEDIUMDígitro NGC Explorer Configuration missing password field maskingEPSS 0.3%CVE-2025-30197LOWJenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attEPSS 0.3%CVE-2022-22550MEDIUMDell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentialEPSS 0.2%CVE-2026-3314MEDIUMMissing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpointEPSS 0.2%CVE-2025-0148LOWZoom Jenkins Marketplace plugin - Missing Password Field MaskingEPSS 0.2%CVE-2025-64170LOWsudo-rs: Partial password reveal is possible after timeoutEPSS 0.1%