Falhas do tipo CWE-259

210 resultados

Senha codificada no código-fonte

É quando credenciais (senhas, tokens, chaves de API) são gravadas diretamente no código-fonte ou em arquivos de configuração versionados. Qualquer pessoa com acesso ao repositório, imagem Docker ou executável consegue extrair a credencial, comprometendo contas e serviços.

Exemplo

Um desenvolvedor escreve `const dbPassword = 'admin123'` no arquivo de conexão ou coloca `API_KEY=sk-1234abcd` em um arquivo .env enviado ao Git. Quando o repositório é clonado ou a imagem é construída, a credencial vira legível para todos.

Como mitigar

Use variáveis de ambiente, gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault) ou arquivos de configuração local não versionados (.env.local). Nunca commite credenciais; implemente scanning de repositórios e revogue qualquer chave exposta.

CVE-2014-5431Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded passEPSS 0.4%CVE-2025-7080MEDIUMDone-0 Jank JWT Token jwt_utils.go hard-coded passwordEPSS 0.4%CVE-2026-25753CRITICALPlaciPy has a Hard-Coded Default Password for All Student Accounts (Account Takeover)EPSS 0.4%CVE-2024-31798MEDIUMIdentical Hardcoded Root Password for All Devices in GNCC's GC2 Indoor Security Camera 1080P allows an attacker with physical access to retrEPSS 0.4%CVE-2018-8870MEDIUMMedtronic MyCareLink Patient Monitor Use of Hard-coded PasswordEPSS 0.4%CVE-2025-9725LOWCudy LT500E Web shadow hard-coded passwordEPSS 0.4%CVE-2024-3700CRITICALHardcoded password in Estomed Sp. z o.o. Simple Care softwareEPSS 0.4%CVE-2026-71809HIGHAuthentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticateEPSS 0.4%CVE-2020-7590A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers EPSS 0.4%CVE-2025-25428HIGHTRENDnet TEW-929DRU 1.0.0.10 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in aEPSS 0.4%CVE-2025-2343HIGHIROAD Dash Cam X5/Dash Cam X6 Device Pairing hard-coded credentialsEPSS 0.4%CVE-2020-12012Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,EPSS 0.3%CVE-2025-47748MEDIUMNetwrix Directory Manager v.11.0.0.0 and before & after v.11.1.25134.03 contains a hardcoded password.EPSS 0.3%CVE-2025-7577MEDIUMTeledyne FLIR FB-Series O/FLIR FH-Series ID hard-coded passwordEPSS 0.3%CVE-2020-12039Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 357EPSS 0.3%CVE-2025-13252MEDIUMshsuishang ShopSuite ModulithShop RSA/OAuth2/Database hard-coded credentialsEPSS 0.3%CVE-2026-6578MEDIUMliangliangyy DjangoBlog Setting settings.py hard-coded credentialsEPSS 0.3%CVE-2024-21990MEDIUMDefault Privileged Account Credentials Vulnerability in ONTAP Select Deploy administration utilityEPSS 0.3%CVE-2023-28895LOWHard-coded password for access to power controller chip memoryEPSS 0.3%CVE-2023-49963HIGHDYMO LabelWriter Print Server through 2.366 contains a backdoor hard-coded password that could allow an attacker to take control.EPSS 0.3%