Fallos del tipo CWE-798

945 resultados

Credenciais codificadas no código-fonte

Senhas, chaves de API ou tokens de autenticação gravados diretamente no código-fonte ou configurações do aplicativo. O atacante que acessa o repositório, binário ou arquivo de configuração obtém acesso imediato aos sistemas protegidos, sem precisar quebrá-los.

Ejemplo

Um desenvolvedor inclui a senha do banco de dados como string literal no código: `const dbPassword = 'admin123';` ou em um arquivo .env commitado no Git. Qualquer pessoa com acesso ao repositório (público ou com vazamento) tem a senha de produção.

Cómo mitigar

Use variáveis de ambiente, gerenciadores de secrets (como Vault, AWS Secrets Manager, Azure Key Vault) e nunca commite credenciais no versionamento. Implemente escaneamento automático de repositórios para detectar padrões de credenciais e revogue chaves encontradas imediatamente.

CVE-2024-0865HIGHCWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administratiEPSS 0.2%CVE-2026-5667HIGHInformation Disclosure, Information Tampering, or Denial-of-Service (DoS) Vulnerability in Multiple Home AppliancesEPSS 0.2%CVE-2024-7206HIGHFirmware extraction and Hardware SSL Pinning BypassEPSS 0.2%CVE-2026-71396MEDIUMUse of Hard-coded Credentials in Bendix EC80 Brake ECUEPSS 0.2%CVE-2023-51588HIGHVoltronic Power ViewPower Pro MySQL Use of Hard-coded Credentials Local Privilege Escalation VulnerabilityEPSS 0.2%CVE-2024-45319MEDIUMA vulnerability in the SonicWall SMA100 SSLVPN firmware 10.2.1.13-72sv and earlier versions allows a remote authenticated attacker can cirEPSS 0.2%CVE-2025-33089MEDIUMMultiple Vulnerabilities in IBM Concert Software.EPSS 0.2%CVE-2024-4844HIGHHardcoded credentials vulnerability in Trellix ePolicy Orchestrator (ePO) on Premise prior to 5.10 Service Pack 1 Update 2 allows an attackeEPSS 0.2%CVE-2026-18931CRITICALHardcoded Credentials in TMT Machine's Talassoft Industrial Management SoftwareEPSS 0.2%CVE-2023-6409HIGH CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with applicatiEPSS 0.2%CVE-2025-30109MEDIUMIn the IROAD APK 5.2.5, there are Hardcoded Credentials in the APK for ports 9091 and 9092. The mobile application for the dashcam contains EPSS 0.2%CVE-2026-22312HIGHUse of Hard-coded Credentials Vulnerability in Radiflow iSAP Smart CollectorEPSS 0.2%CVE-2025-7564HIGHLB-LINK BL-AC3600 shadow hard-coded credentialsEPSS 0.2%CVE-2024-35118MEDIUMIBM MaaS360 information disclosureEPSS 0.2%CVE-2022-22765HIGHBD Viper LT System - Hardcoded CredentialsEPSS 0.2%CVE-2026-13728MEDIUMWatchGuard Firebox Hardcoded Fallback Encryption Key in Access Portal Resource Credential DatabaseEPSS 0.2%CVE-2026-76392MEDIUMUse of Hard-coded Credentials in Container Connections in Splunk AI ToolkitEPSS 0.2%CVE-2026-11746CRITICALA vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting reEPSS 0.2%CVE-2021-42849MEDIUMA weak default password for the serial port was reported in some Lenovo Personal Cloud Storage devices that could allow unauthorized device EPSS 0.2%CVE-2025-68421HIGHHardcoded credentials in Comarch ERP OptimaEPSS 0.2%