Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2022-32520HIGHA CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed oEPSS 0.5%CVE-2022-32518HIGHA CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed oEPSS 0.5%CVE-2022-43969CRITICALRicoh mp_c4504ex devices with firmware 1.06 mishandle credentials.EPSS 0.5%CVE-2022-43460HIGHDriver Distributor v2.2.3.1 and earlier contains a vulnerability where passwords are stored in a recoverable format. If an attacker obtains EPSS 0.5%CVE-2022-29089MEDIUMDell Networking OS10, versions prior to October 2021 with Smart Fabric Services enabled, contains an information disclosure vulnerability. AEPSS 0.5%CVE-2026-23958HIGHDataEase Vulnerable to Brute-Force Attack on Admin JWT Secret Derived from Password that Enables Full Account TakeoverEPSS 0.5%CVE-2022-40685MEDIUMInsufficiently protected credentials in the Intel(R) DCM software before version 5.0.1 may allow an authenticated user to potentially enableEPSS 0.5%CVE-2023-25740HIGHAfter downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unEPSS 0.5%CVE-2026-23742HIGHSkipper arbitrary code execution through lua filtersEPSS 0.5%CVE-2024-22345MEDIUMIBM TXSeries for Multiplatforms information disclosureEPSS 0.5%CVE-2024-34147MEDIUMJenkins Telegram Bot Plugin 1.4.0 and earlier stores the Telegram Bot token unencrypted in its global configuration file on the Jenkins contEPSS 0.5%CVE-2025-6519CRITICALConsistent predictable generation of the password for the default admin user "ONEDAY" to the application servicesEPSS 0.5%CVE-2024-8986CRITICALInformation Leakage in grafana-plugin-sdk-goEPSS 0.5%CVE-2025-64420CRITICALCoolify members can see private key of root userEPSS 0.5%CVE-2023-28764LOWInformation Disclosure vulnerability in SAP BusinessObjects PlatformEPSS 0.5%CVE-2026-69805HIGH.NET Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2023-32988MEDIUMA missing permission check in Jenkins Azure VM Agents Plugin 852.v8d35f0960a_43 and earlier allows attackers with Overall/Read permission toEPSS 0.5%CVE-2022-41247MEDIUMJenkins BigPanda Notifier Plugin 1.4.0 and earlier stores the BigPanda API key unencrypted in its global configuration file on the Jenkins cEPSS 0.5%CVE-2021-33589HIGHRibose RNP before 0.15.1 does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than on the tin of EPSS 0.5%CVE-2023-31136LOWPostgresNIO processes unencrypted bytes from man-in-the-middleEPSS 0.5%