Fallos del tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

Ocorre quando dados sensíveis (senhas, tokens, chaves, dados pessoais) são armazenados sem proteção adequada — em texto plano, em cache, em arquivos acessíveis ou em memória não cifrada. Um atacante que ganha acesso ao sistema consegue recuperar essas informações diretamente, comprometendo contas, autenticação e privacidade.

Ejemplo

Uma aplicação móvel salva o token de autenticação em SharedPreferences (Android) ou UserDefaults (iOS) sem encriptação; ou um servidor escreve senhas em arquivos de log; ou credenciais ficam em variáveis de ambiente em histórico de shell — tudo recuperável por quem tiver acesso ao dispositivo ou servidor.

Cómo mitigar

Use APIs de armazenamento seguro: Keychain (iOS), Keystore (Android), DPAPI (Windows), ou cofres de secrets (Vault, AWS Secrets Manager). Nunca registre dados sensíveis em logs. Cifre dados em repouso com padrões reconhecidos (AES-256) e remova do histórico e cache tudo que não for necessário manter.

CVE-2025-11639MEDIUMTomofun Furbo 360/Furbo Mini Debug Log S3 Bucket collect_logs.sh sensitive informationEPSS 0.2%CVE-2026-26152HIGHMicrosoft Cryptographic Services Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2021-25402Information Exposure vulnerability in Samsung Notes prior to version 4.2.04.27 allows attacker to access s pen latency information.EPSS 0.2%CVE-2024-32211MEDIUMAn issue in LOGINT LoMag Inventory Management v1.0.20.120 and before allows a local attacker to obtain sensitive information via the UserClaEPSS 0.2%CVE-2025-43203MEDIUMThe issue was addressed with improved handling of caches. This issue is fixed in iOS 18.7 and iPadOS 18.7, iOS 26 and iPadOS 26. An attackerEPSS 0.2%CVE-2024-44275LOWThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.1, macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A maliciEPSS 0.2%CVE-2024-51399MEDIUMAltai Technologies Ltd Altai IX500 Indoor 22 802.11ac Wave 2 AP After login, there are file reads in the background, and attackers can obtaiEPSS 0.2%CVE-2021-25524MEDIUMInsecure storage of device information in Contacts prior to version 12.7.05.24 allows attacker to get Samsung Account ID.EPSS 0.2%CVE-2021-25523MEDIUMInsecure storage of device information in Samsung Dialer prior to version 12.7.05.24 allows attacker to get Samsung Account ID.EPSS 0.2%CVE-2024-30917MEDIUMAn issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensiEPSS 0.2%CVE-2024-30122MEDIUMHCL Sametime is impacted by misconfigured security related HTTP headersEPSS 0.2%CVE-2025-10734MEDIUMReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More <= 2.2.12 - Unauthenticated Sensitive Information ExposureEPSS 0.2%CVE-2024-35526MEDIUMAn issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directoryEPSS 0.2%CVE-2024-44263MEDIUMA logic issue was addressed with improved state management. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to access usEPSS 0.2%CVE-2024-23232LOWA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Sonoma 14.4. An app may be able to capEPSS 0.2%CVE-2024-23205MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS SEPSS 0.2%CVE-2024-13954MEDIUMSerialization / Deserialization of configuration dataEPSS 0.2%CVE-2022-28170MEDIUMBrocade Fabric OS Web Application services before Brocade Fabric v9.1.0, v9.0.1e, v8.2.3c, v7.4.2j store server and user passwords in the deEPSS 0.2%CVE-2024-44298MEDIUMA privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.1. An app may beEPSS 0.2%CVE-2024-6295LOWudn News App - Insecure Data StorageEPSS 0.2%