Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2016-10603air-sdk is a NPM wrapper for the Adobe AIR SDK. air-sdk downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. ItEPSS 1.8%CVE-2016-10605dalek-browser-ie is Internet Explorer bindings for DalekJS. dalek-browser-ie downloads binary resources over HTTP, which leaves it vulnerablEPSS 1.8%CVE-2016-10621fibjs is a runtime for javascript applictions built on google v8 JS. fibjs downloads binary resources over HTTP, which leaves it vulnerable EPSS 1.8%CVE-2016-10575Kindlegen is a simple Node.js wrapper of the official kindlegen program. Kindlegen versions before 1.1.0 download binary resources over HTTPEPSS 1.8%CVE-2016-10570pngcrush-installer is an installer for Pngcrush. pngcrush-installer versions below 1.8.10 download binary resources over HTTP, which leaves EPSS 1.7%CVE-2016-10674limbus-buildgen is a "build anywhere" build system. limbus-buildgen versions below 0.1.1 download binary resources over HTTP, which leaves iEPSS 1.7%CVE-2016-10560galenframework-cli is the node wrapper for the Galen Framework. galenframework-cli below 2.3.1 download binary resources over HTTP, which leEPSS 1.7%CVE-2016-10688Haxe 3 : The Cross-Platform Toolkit (a fork from David Mouton's damoebius/haxe-npm) haxe3 downloads resources over HTTP, which leaves it vulEPSS 1.7%CVE-2016-10658native-opencv is the OpenCV library installed via npm native-opencv downloads binary resources over HTTP, which leaves it vulnerable to MITMEPSS 1.7%CVE-2016-10690openframe-ascii-image module is an openframe plugin which adds support for ascii images via fim. openframe-ascii-image downloads resources oEPSS 1.7%CVE-2016-10656qbs is a build tool that helps simplify the build process for developing projects across multiple platforms. qbs downloads binary resources EPSS 1.7%CVE-2016-10672cloudpub-redis is a module for CloudPub: Redis Backend cloudpub-redis downloads binary resources over HTTP, which leaves it vulnerable to MIEPSS 1.7%CVE-2016-10651webdriver-launcher is a Node.js Selenium Webdriver Launcher. webdriver-launcher downloads binary resources over HTTP, which leaves it vulnerEPSS 1.7%CVE-2016-10607openframe-glsviewer is a Openframe extension which adds support for shaders via glslViewer. openframe-glsviewer downloads binary resources oEPSS 1.7%CVE-2016-10606grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, whiEPSS 1.7%CVE-2016-10682massif is a Phantomjs fork massif downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remEPSS 1.7%CVE-2016-10631jvminstall is a module for downloading and unpacking jvm to local system. jvminstall downloads binary resources over HTTP, which leaves it vEPSS 1.7%CVE-2016-10629nw-with-arm is a NW Installer including ARM-Build. nw-with-arm downloads binary resources over HTTP, which leaves it vulnerable to MITM attaEPSS 1.7%CVE-2016-10580nodewebkit is an installer for node-webkit. nodewebkit downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It EPSS 1.7%CVE-2016-10638js-given is a JavaScript frontend to jgiven. js-given downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It mEPSS 1.7%