Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-55870LOWGoCD is vulnerable to credential exposure when admins insecurely configure material URLsEPSS 0.2%CVE-2026-33575HIGHOpenClaw < 2026.3.12 - Long-lived Credential Exposure in Pairing Setup CodesEPSS 0.2%CVE-2019-10139MEDIUMDuring HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-setup/cockpit/ansibleEPSS 0.2%CVE-2026-0393MEDIUMCODESYS Visualization - Insufficiently Protected CredentialsEPSS 0.2%CVE-2026-27777MEDIUMMobiliti e-mobi.hu Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-53657MEDIUMJenkins ReadyAPI Functional Testing Plugin 1.11 and earlier does not mask SLM License Access Keys, client secrets, and passwords displayed oEPSS 0.2%CVE-2025-53660MEDIUMJenkins QMetry Test Management Plugin 1.13 and earlier does not mask Qmetry Automation API Keys displayed on the job configuration form, incEPSS 0.2%CVE-2026-54660HIGHswagger-typescript-api vulnerable to authorization-token exfiltration via spec `$ref`EPSS 0.2%CVE-2026-72793CRITICALSiYuan before v3.7.4 Information Disclosure via /api/system/getConfEPSS 0.2%CVE-2026-76846HIGHGrav before 2.0.16 Information Disclosure via Twig SandboxEPSS 0.2%CVE-2026-72801HIGHSiYuan before v3.7.4 Information Disclosure via Encryption Key MaterialEPSS 0.2%CVE-2025-53661MEDIUMJenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing EPSS 0.2%CVE-2026-14564CRITICALSensitive Data Exposure in Innotim Software's Logsign SIEMEPSS 0.2%CVE-2026-71511HIGHDolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member EndpointsEPSS 0.2%CVE-2022-33954MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.2%CVE-2026-82070HIGHInsufficiently Protected Credentials in MongoDB Server Diagnostic Reporting InterfaceEPSS 0.2%CVE-2023-50436MEDIUMAn issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The eEPSS 0.2%CVE-2026-28961MEDIUMThis issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS Tahoe 26.5. An attackEPSS 0.2%CVE-2025-69271LOWSpectrum basic authentication in useEPSS 0.2%CVE-2021-22781—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%