Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2025-55262HIGHHCL Aftermarket DPC is affected by SQL InjectionEPSS 0.3%CVE-2022-38117MEDIUMJuiker app - Hard-coded CredentialsEPSS 0.3%CVE-2025-41722HIGHSauter: Hard-coded Authentication CredentialsEPSS 0.3%CVE-2025-34197HIGHVasion Print (formerly PrinterLogic) Undocumented Local Account with Hardcoded Password and Passwordless sudoEPSS 0.3%CVE-2024-55927HIGHFlawed token generation implementation & Hard-coded key implementationEPSS 0.3%CVE-2024-8449MEDIUMPLANET Technology switch devices - Local users' passwords recovery through hard-coded credentialsEPSS 0.3%CVE-2024-28146HIGHHardcoded credentialsEPSS 0.3%CVE-2026-65313HIGHUse of hard-coded VNC credentials in the engineering-workstation provisioningEPSS 0.3%CVE-2026-3873HIGHLegacy built-in user accountEPSS 0.3%CVE-2026-49204MEDIUMHard-coded AWS Cognito Testing AccountsEPSS 0.3%CVE-2026-17038MEDIUMUse of Hard-coded Credentials in drEryk GabinetEPSS 0.3%CVE-2024-29170HIGHDell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticaEPSS 0.3%CVE-2026-96548MEDIUMsfturing hosp_order jdbc.properties hard-coded credentialsEPSS 0.3%CVE-2025-31953HIGHHCL iAutomate is affected by hardcoded credentialsEPSS 0.3%CVE-2025-4633MEDIUMDefault CredentialsEPSS 0.3%CVE-2020-7515—A CWE-321: Use of hard-coded cryptographic key stored in cleartext vulnerability exists in Easergy Builder V1.4.7.2 and prior which could alEPSS 0.3%CVE-2021-1219HIGHCisco Smart Software Manager Satellite Static Credential VulnerabilityEPSS 0.3%CVE-2024-27159MEDIUMHardcoded password used to encrypt logsEPSS 0.3%CVE-2025-0642MEDIUMHard-coded Credentials in PosCube's AssistEPSS 0.3%CVE-2024-41777HIGHIBM Cognos Controller hard coded credentialsEPSS 0.3%