Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-20733MEDIUMCloudCharge cloudcharge.se Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-76839HIGHGrav before 2.0.16 Information Disclosure via offsetGetEPSS 0.3%CVE-2019-10205MEDIUMA flaw was found in the way Red Hat Quay stores robot account tokens in plain text. An attacker able to perform database queries in the Red EPSS 0.3%CVE-2024-28981HIGHHitachi Vantara Pentaho Data Integration & Analytics - Insufficiently Protected CredentialsEPSS 0.3%CVE-2026-39968HIGHTypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview EndpointEPSS 0.3%CVE-2023-24619MEDIUMRedpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and SecretEPSS 0.3%CVE-2026-8368MEDIUMLWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirectsEPSS 0.3%CVE-2026-55885MEDIUMGrav: Admin Backup Zip File Exposes Account Credentials and Configuration SecretsEPSS 0.3%CVE-2024-51240HIGHAn issue in the luci-mod-rpc package in OpenWRT Luci LTS allows for privilege escalation from an admin account to root via the JSON-RPC-API,EPSS 0.3%CVE-2025-53743MEDIUMJenkins Applitools Eyes Plugin 1.16.5 and earlier does not mask Applitools API keys displayed on the job configuration form, increasing the EPSS 0.3%CVE-2025-52545HIGHPrivilege escalation in the application servicesEPSS 0.3%CVE-2026-15657MEDIUMforeUP customer REST API allows authenticated users to read cleartext payment-processor merchant credentialsEPSS 0.3%CVE-2026-86175HIGHNetBox through 4.7.0 Credential Disclosure via REST and GraphQL APIsEPSS 0.3%CVE-2026-86726HIGHAVideo through 29.0 Information Disclosure via restreamsActive.json.phpEPSS 0.3%CVE-2024-47142MEDIUMAIPHONE IXG SYSTEM IXG-2C7 firmware Ver.2.03 and earlier and IXG-2C7-L firmware Ver.2.03 and earlier contain an issue with insufficiently prEPSS 0.3%CVE-2025-53008MEDIUMGLPI's MailCollector Receiver is vulnerable to credential exfiltrationEPSS 0.3%CVE-2020-7307MEDIUMDLP for Mac - Unprotected Storage of CredentialsEPSS 0.3%CVE-2023-41926HIGHInsufficiently protected credentials in Kiloview P1/P2 devicesEPSS 0.3%CVE-2026-41506MEDIUMgo-git Credential leak via cross-host redirect in smart HTTP transportEPSS 0.3%CVE-2019-3938—Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configuration options in the fEPSS 0.3%