Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2025-29314HIGHInsecure Shiro cookie configurations in OpenDaylight Service Function Chaining (SFC) Subproject SFC Sodium-SR4 and below allow attackers to EPSS 0.2%CVE-2025-53678MEDIUMJenkins User1st uTester Plugin 1.1 and earlier stores the uTester JWT token unencrypted in its global configuration file on the Jenkins contEPSS 0.2%CVE-2025-53676MEDIUMJenkins Xooa Plugin 0.0.7 and earlier stores the Xooa Deployment Token unencrypted in its global configuration file on the Jenkins controlleEPSS 0.2%CVE-2025-53673MEDIUMJenkins Sensedia Api Platform tools Plugin 1.0 stores the Sensedia API Manager integration token unencrypted in its global configuration filEPSS 0.2%CVE-2020-7567HIGHA CWE-311: Missing Encryption of Sensitive Data vulnerability exists in Modicon M221 (all references, all versions) that could allow the attEPSS 0.2%CVE-2024-23444MEDIUMElasticsearch elasticsearch-certutil csr fails to encrypt private keyEPSS 0.2%CVE-2024-25631MEDIUMUnencrypted traffic between pods when using Wireguard and an external kvstoreEPSS 0.2%CVE-2026-81688HIGHopenssl_encrypt before 1.4.9 Plaintext Confirmation Oracle via SHA-256EPSS 0.2%CVE-2025-53653MEDIUMJenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the JenkinsEPSS 0.2%CVE-2023-30561MEDIUMLack of Cryptographic Security of IUI Bus EPSS 0.2%CVE-2024-40620MEDIUMRockwell Automation Pavilion8® Unencrypted Data Vulnerability via HTTP protocolEPSS 0.2%CVE-2024-25630MEDIUMCilium has unencrypted ingress/health traffic when using Wireguard transparent encryptionEPSS 0.2%CVE-2025-64143MEDIUMJenkins OpenShift Pipeline Plugin 1.0.57 and earlier stores authorization tokens unencrypted in job config.xml files on the Jenkins controllEPSS 0.2%CVE-2026-53442MEDIUMJenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before storing them in job confEPSS 0.2%CVE-2023-28045MEDIUM Dell CloudIQ Collector version 1.10.2 contains a missing encryption of sensitive data vulnerability. An attacker with low privileges could EPSS 0.2%CVE-2023-6339CRITICALGoogle Nest WiFi Pro root code-execution & user-data compromiseEPSS 0.2%CVE-2018-8864In ATI Systems Emergency Mass Notification Systems (HPSS16, HPSS32, MHPSS, and ALERT4000) devices, a missing encryption of sensitive data vuEPSS 0.2%CVE-2024-47871HIGHInsecure communication between the FRP client and server in GradioEPSS 0.2%CVE-2020-9062Diebold Nixdorf ProCash 2100xe USB ATMs running Wincor Probase version 1.1.30 do not encrypt, authenticate, or verify the integrity of messaEPSS 0.2%CVE-2024-28250MEDIUMCilium has possible unencrypted traffic between nodes when using WireGuard and L7 policiesEPSS 0.2%