Falhas do tipo CWE-319

539 resultados

Transmissão de dados sensíveis em texto plano

A aplicação envia informações sensíveis (senhas, tokens, dados pessoais) sem criptografia em um canal de comunicação que pode ser interceptado. Um atacante na rede consegue capturar esses dados facilmente com ferramentas simples como packet sniffers, comprometendo a confidencialidade.

Exemplo

Uma API envia credenciais de usuário via HTTP simples em vez de HTTPS, ou um sistema transmite tokens de autenticação em requisições GET visíveis em logs de proxy. Um atacante na mesma rede Wi-Fi captura os pacotes e acessa as credenciais diretamente.

Como mitigar

Use HTTPS/TLS em todas as comunicações envolvendo dados sensíveis, implemente criptografia end-to-end quando necessário, e nunca transmita credenciais em parâmetros de URL. Valide certificados SSL/TLS do lado cliente e revise protocolos legados (FTP, Telnet) para alternativas seguras.

CVE-2025-57727MEDIUMIn JetBrains IntelliJ IDEA before 2025.2 credentials disclosure was possible via remote referenceEPSS 0.2%CVE-2025-44612MEDIUMTinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device creEPSS 0.2%CVE-2024-8059MEDIUMIPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.EPSS 0.2%CVE-2019-6540MEDIUMMedtronic Conexus Radio Frequency Telemetry Protocol Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-44251HIGHEcovacs Deebot T10 1.7.2 transmits Wi-Fi credentials in cleartext during the pairing process.EPSS 0.2%CVE-2026-27752HIGHSODOLA SL902-SWTGW124AS <= 200.1.20 Cleartext Credential TransmissionEPSS 0.2%CVE-2023-24440MEDIUMJenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier transmits the private key in plain text as part of the global Jenkins cEPSS 0.2%CVE-2025-13489MEDIUMIBM DevOps Deploy is susceptible to a Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2023-3028HIGHImproper backend communication allows access and manipulation of the telemetry dataEPSS 0.2%CVE-2025-12508HIGHUnencrypted communication to Active Directory servicesEPSS 0.2%CVE-2026-40431MEDIUMSenseLive X3050 Cleartext transmission of sensitive informationEPSS 0.2%CVE-2026-81836MEDIUMRooCodeInc Roo-Code OAuth Callback oauth.ts cleartext transmissionEPSS 0.2%CVE-2026-33569MEDIUMAnviz Products Cleartext Transmission of Sensitive InformationEPSS 0.2%CVE-2025-64648MEDIUMMultiple Vulnerabilities in IBM Concert SoftwareEPSS 0.2%CVE-2026-43625HIGHCodexBar < 0.32.0 Session Cookie Exposure via HTTP RedirectEPSS 0.2%CVE-2025-13490MEDIUMIBM App Connect Enterprise Certified Container IntegrationServer and IntegrationRuntime operands that report metrics are vulnerable to loss of confidentialityEPSS 0.2%CVE-2025-70048HIGHAn issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.EPSS 0.2%CVE-2026-50200HIGHSteeltoe's env sanitizer misses connection strings — leaks embedded DB passwordsEPSS 0.2%CVE-2025-13718LOWIBM Sterling Partner Engagement Manager Information DisclosureEPSS 0.2%CVE-2025-52490HIGHAn issue was discovered in Couchbase Sync Gateway before 3.2.6. In sgcollect_info_options.log and sync_gateway.log, there are cleartext passEPSS 0.2%