Falhas do tipo CWE-311

312 resultados

Falta de criptografia de dados sensíveis

A aplicação transmite ou armazena dados sensíveis (senhas, tokens, dados pessoais, números de cartão) em texto plano, sem criptografia. Um atacante que intercepte a comunicação ou acesse o armazenamento consegue ler essas informações diretamente, comprometendo confidencialidade e segurança do usuário.

Exemplo

Um aplicativo mobile envia credenciais de login via HTTP em vez de HTTPS, ou salva senhas em um arquivo de configuração sem criptografia. Um atacante na mesma rede Wi-Fi ou com acesso ao dispositivo rouba as credenciais facilmente.

Como mitigar

Use HTTPS/TLS para toda comunicação de dados sensíveis, criptografe dados em repouso com algoritmos fortes (AES-256), e nunca armazene senhas em texto plano — use hash com salt (bcrypt, argon2). Aplique essas práticas no design, não como remendo.

CVE-2016-10626mystem3 is a NodeJS wrapper for the Yandex MyStem 3. mystem3 downloads binary resources over HTTP, which leaves it vulnerable to MITM attackEPSS 1.7%CVE-2016-10646resourcehacker is a Node wrapper of Resource Hacker (windows executable resource editor). resourcehacker downloads binary resources over HTTEPSS 1.7%CVE-2016-10689The windows-iedriver module downloads fixed version of iedriverserver.exe windows-iedriver downloads binary resources over HTTP, which leaveEPSS 1.7%CVE-2016-10671mystem-wrapper is a Yandex mystem app wrapper module. mystem-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITEPSS 1.7%CVE-2016-10635broccoli-closure is a Closure compiler plugin for Broccoli. broccoli-closure before 1.3.1 downloads binary resources over HTTP, which leavesEPSS 1.7%CVE-2016-10582closurecompiler is a Closure Compiler for node.js. closurecompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM EPSS 1.7%CVE-2016-10643jstestdriver is a wrapper for Google's jstestdriver. jstestdriver downloads binary resources over HTTP, which leaves it vulnerable to MITM aEPSS 1.7%CVE-2016-10638js-given is a JavaScript frontend to jgiven. js-given downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It mEPSS 1.7%CVE-2016-10617box2d-native downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execuEPSS 1.7%CVE-2016-10567product-monitor is a HTML/JavaScript template for monitoring a product by encouraging product developers to gather all the information aboutEPSS 1.7%CVE-2016-10666tomita-parser is a Node wrapper for Yandex Tomita Parser tomita-parser downloads binary resources over HTTP, which leaves it vulnerable to MEPSS 1.7%CVE-2016-10672cloudpub-redis is a module for CloudPub: Redis Backend cloudpub-redis downloads binary resources over HTTP, which leaves it vulnerable to MIEPSS 1.7%CVE-2016-10606grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, whiEPSS 1.7%CVE-2016-10602haxe is a cross-platform toolkit haxe downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible tEPSS 1.7%CVE-2016-10660fis-parser-sass-bin a plugin for fis to compile sass using node-sass-binaries. fis-parser-sass-bin downloads binary resources over HTTP, whiEPSS 1.7%CVE-2016-10696windows-latestchromedriver downloads the latest version of chromedriver.exe. windows-latestchromedriver downloads binary resources over HTTPEPSS 1.7%CVE-2016-10662tomita is a node wrapper for Yandex Tomita Parser tomita downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. IEPSS 1.7%CVE-2016-10683arcanist downloads resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) EPSS 1.7%CVE-2016-10576Fuseki server wrapper and management API in fuseki before 1.0.1 downloads binary resources over HTTP, which leaves it vulnerable to MITM attEPSS 1.7%CVE-2017-16040gfe-sass is a library for promises (CommonJS/Promises/A,B,D) gfe-sass downloads resources over HTTP, which leaves it vulnerable to MITM attaEPSS 1.7%