Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-67426CRITICALFlyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltrationEPSS 0.3%CVE-2024-47161MEDIUMIn JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST APIEPSS 0.3%CVE-2022-36307—The AirVelocity 1500 prints SNMP credentials on its physically accessible serial port during boot. This was fixed in AirVelocity 1500 softwaEPSS 0.3%CVE-2026-54276MEDIUMAIOHTTP: DigestAuthMiddleware Applies Credentials to Cross-Origin Redirect ChallengesEPSS 0.3%CVE-2026-1433MEDIUMuniFLOW Universal Login Manager (ULM) Standalone Improper Protection of Sensitive Information Leads to Information DisclosureEPSS 0.3%CVE-2026-14019MEDIUMInappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a EPSS 0.3%CVE-2020-16097HIGHOn controllers running versions of v8.20 prior to vCR8.20.200221b (distributed in v8.20.1093(MR2)), v8.10 prior to vGR8.10.179 (distributed EPSS 0.3%CVE-2026-27316LOWA insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbEPSS 0.3%CVE-2026-34262MEDIUMInformation Disclosure Vulnerability in SAP HANA Cockpit and HANA Database ExplorerEPSS 0.3%CVE-2021-47726HIGHNuCom 11N Wireless Router 5.07.90 Privilege Escalation via Configuration BackupEPSS 0.3%CVE-2022-43442MEDIUMPlaintext storage of a password vulnerability exists in +F FS040U software versions v2.3.4 and earlier, which may allow an attacker to obtaiEPSS 0.3%CVE-2026-28204MEDIUMCTEK Chargeportal Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-36096CRITICALAIX Insufficiently Protected CredentialsEPSS 0.3%CVE-2025-14148MEDIUMIBM DevOps Deploy is susceptible to a Insufficiently Protected Credentials vulnerabilityEPSS 0.3%CVE-2026-20791MEDIUMChargemap chargemap.com Insufficiently Protected CredentialsEPSS 0.3%CVE-2024-56354MEDIUMIn JetBrains TeamCity before 2024.12 password field value were accessible to users with view settings permissionEPSS 0.3%CVE-2026-82247HIGHgitoxide before 0.37.1 HTTP Basic credential leak via URL parsingEPSS 0.3%CVE-2026-22890MEDIUMEV2GO ev2go.io Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-47662HIGHPathling $bulk-submit allows bearer-token exfiltration and persistent warehouse poisoning via unvalidated manifest output URLsEPSS 0.3%CVE-2026-55188HIGHRustFS: ListRemoteTargetHandler authorization bypass leaks replication target credentialsEPSS 0.3%