Fallos del tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

Ocorre quando dados sensíveis (senhas, tokens, chaves, dados pessoais) são armazenados sem proteção adequada — em texto plano, em cache, em arquivos acessíveis ou em memória não cifrada. Um atacante que ganha acesso ao sistema consegue recuperar essas informações diretamente, comprometendo contas, autenticação e privacidade.

Ejemplo

Uma aplicação móvel salva o token de autenticação em SharedPreferences (Android) ou UserDefaults (iOS) sem encriptação; ou um servidor escreve senhas em arquivos de log; ou credenciais ficam em variáveis de ambiente em histórico de shell — tudo recuperável por quem tiver acesso ao dispositivo ou servidor.

Cómo mitigar

Use APIs de armazenamento seguro: Keychain (iOS), Keystore (Android), DPAPI (Windows), ou cofres de secrets (Vault, AWS Secrets Manager). Nunca registre dados sensíveis em logs. Cifre dados em repouso com padrões reconhecidos (AES-256) e remova do histórico e cache tudo que não for necessário manter.

CVE-2025-53507HIGHMultiple products provided by iND Co.,Ltd contain an insecure storage of sensitive information vulnerability. If exploited, configuration inEPSS 0.3%CVE-2024-31404MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to theEPSS 0.3%CVE-2026-5666MEDIUMcode-projects Online FIR System SQL Database Backup File complaints.sql sensitive informationEPSS 0.3%CVE-2025-28171MEDIUMAn issue in Grandstream UCM6510 v.1.0.20.52 and before allows a remote attacker to obtain sensitive information via the Login function at /cEPSS 0.3%CVE-2024-29953MEDIUMEncoded session passwords on session storage for Virtual Fabric platformsEPSS 0.3%CVE-2023-23522MEDIUMA privacy issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.2.1. An app may be able to EPSS 0.3%CVE-2024-38312MEDIUMWhen browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed EPSS 0.3%CVE-2026-40868HIGHkyverno apicall servicecall implicit bearer token injection leaks kyverno serviceaccount tokenEPSS 0.3%CVE-2024-54485MEDIUMThe issue was addressed by adding additional logic. This issue is fixed in iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, macOS Sequoia 15.2. An aEPSS 0.3%CVE-2024-49201MEDIUMKeyfactor Remote File Orchestrator (aka remote-file-orchestrator) 2.8 before 2.8.1 allows Information Disclosure: sensitive information coulEPSS 0.3%CVE-2024-31400MEDIUMInsertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintenEPSS 0.3%CVE-2024-29120MEDIUMApache StreamPark: Information leakage vulnerabilityEPSS 0.3%CVE-2025-11644LOWTomofun Furbo 360/Furbo Mini UART sensitive informationEPSS 0.3%CVE-2025-70963HIGHGophish <=0.12.1 is vulnerable to Incorrect Access Control. The administrative dashboard exposes each user’s long-lived API key directly insEPSS 0.3%CVE-2026-46511HIGHHAXcms: Mass Token Exfiltration and Cross-Tenant HijackEPSS 0.3%CVE-2024-23229MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Monterey 12.7.5, macOS Sonoma 14.4, EPSS 0.3%CVE-2024-54477MEDIUMThe issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2, macOS Ventura 13.7.2. An app mEPSS 0.3%CVE-2025-24117MEDIUMThis issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, mEPSS 0.3%CVE-2024-42677MEDIUMAn issue in Huizhi enterprise resource management system v.1.0 and before allows a local attacker to obtain sensitive information via the /nEPSS 0.3%CVE-2024-36788MEDIUMNetgear WNR614 JNR1010V2 N300-V1.1.0.54_1.0.1 does not properly set the HTTPOnly flag for cookies. This allows attackers to possibly interceEPSS 0.3%