Fallos del tipo CWE-798

942 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2026-45336CRITICALHireFlow: Use of Hard-coded CredentialsEPSS 0.6%CVE-2023-51840CRITICALDoraCMS 2.1.8 is vulnerable to Use of Hard-coded Cryptographic Key.EPSS 0.6%CVE-2022-37832CRITICALMutiny 7.2.0-10788 suffers from Hardcoded root password.EPSS 0.6%CVE-2021-0279HIGHContrail Cloud: Hardcoded credentials for RabbitMQ serviceEPSS 0.6%CVE-2018-25138CRITICALFLIR AX8 Thermal Camera 1.32.16 Hard-Coded Credentials Authentication BypassEPSS 0.6%CVE-2024-51547CRITICALCredentials Disclosure - keysEPSS 0.6%CVE-2024-41794CRITICALA vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). Affected devices contain hardcoded credentials for rEPSS 0.6%CVE-2025-34034CRITICAL5VTechnologies Blue Angel Software Suite Hardcoded CredentialsEPSS 0.6%CVE-2022-47891HIGHAdmin password reset in NetMan 204EPSS 0.6%CVE-2023-47704MEDIUMIBM Security Guardium Key Lifecycle Manager information disclosureEPSS 0.6%CVE-2025-10850CRITICALFelan Framework <= 1.1.4 - Hardcoded CredentialsEPSS 0.6%CVE-2025-28388CRITICALOpenC3 COSMOS before v6.0.2 was discovered to contain hardcoded credentials for the Service Account.EPSS 0.6%CVE-2023-23132HIGHSelfwealth iOS mobile App 3.3.1 is vulnerable to Sensitive key disclosure. The application reveals hardcoded API keys.EPSS 0.6%CVE-2025-6950CRITICALAn Use of Hard-coded Credentials vulnerability has been identified in Moxa’s network security appliances and routers. The system employs a hEPSS 0.6%CVE-2026-55579CRITICALPheditor: Hardcoded default password 'admin' with no forced change enables full application compromiseEPSS 0.6%CVE-2026-49352CRITICAL9Router: Hardcoded Default fallback JWT Secret Allows Authentication BypassEPSS 0.6%CVE-2025-45466HIGHUnitree Go1 <= Go1_2022_05_11 is vulnerale to Incorrect Access Control due to authentication credentials being hardcoded in plaintext.EPSS 0.6%CVE-2023-33778CRITICALDraytek Vigor Routers firmware versions below 3.9.6/4.2.4, Access Points firmware versions below v1.4.0, Switches firmware versions below 2.EPSS 0.6%CVE-2025-57579HIGHAn issue in TOTOLINK Wi-Fi 6 Router Series Device X2000R-Gh-V2.0.0 allows a remote attacker to execute arbitrary code via the default passwoEPSS 0.6%CVE-2022-22466MEDIUMIBM Security Verify Governance information disclosureEPSS 0.6%