Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2026-41715MEDIUMReactor Netty HTTP Client Leaks Credentials On Protocol Downgrade RedirectEPSS 0.2%CVE-2025-53661MEDIUMJenkins Testsigma Test Plan run Plugin 1.6 and earlier does not mask Testsigma API keys displayed on the job configuration form, increasing EPSS 0.2%CVE-2022-33954MEDIUMIBM Robotic Process Automation information disclosureEPSS 0.2%CVE-2023-50436MEDIUMAn issue was discovered in Couchbase Server before 7.2.4. ns_server admin credentials are leaked in encoded form in the diag.log file. The eEPSS 0.2%CVE-2021-22781—Insufficiently Protected Credentials vulnerability exists in EcoStruxure Control Expert (all versions prior to V15.0 SP1, including all versEPSS 0.2%CVE-2025-69271LOWSpectrum basic authentication in useEPSS 0.2%CVE-2026-0715HIGHMoxa Arm-based industrial computers running Moxa Industrial Linux Secure use a device-unique bootloader password provided on the device. An EPSS 0.2%CVE-2024-46341HIGHTP-Link TL-WR845N(UN)_V4_190219 was discovered to transmit credentials in base64 encoded form, which can be easily decoded by an attacker exEPSS 0.2%CVE-2023-6259HIGHLocal Access to Sensitive Data in Brivo ACS100 and ACS300 EPSS 0.2%CVE-2025-53669MEDIUMJenkins VAddy Plugin 1.2.8 and earlier does not mask Vaddy API Auth Keys displayed on the job configuration form, increasing the potential fEPSS 0.2%CVE-2026-42951MEDIUMMacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected CredentialsEPSS 0.2%CVE-2025-37728MEDIUMKibana Insufficiently Protected Credentials in the CrowdStrike ConnectorEPSS 0.2%CVE-2026-11921CRITICALSecurity vulnerabilities have been addressed in IBM Verify Identity Access and IBM Security Verify AccessEPSS 0.2%CVE-2025-42897MEDIUMInformation Disclosure vulnerability in SAP Business One (SLD)EPSS 0.2%CVE-2022-38465CRITICALA vulnerability has been identified in SIMATIC Drive Controller family (All versions < V2.9.2), SIMATIC ET 200SP Open Controller CPU 1515SP EPSS 0.2%CVE-2026-32634HIGHGlances Central Browser Autodiscovery Leaks Reusable Credentials to Zeroconf-Spoofed ServersEPSS 0.2%CVE-2020-10710—A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This EPSS 0.2%CVE-2026-92133MEDIUMJenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API token credentials undeEPSS 0.2%CVE-2026-55860MEDIUMMariaDB Connector/R2DBC: Cleartext password disclosure to a man-in-the-middle server (clear-text auth plugins not gated on a secure transport)EPSS 0.2%CVE-2026-81208HIGHDataStage on Cloud Pak for Data has several vulnerabilitiesEPSS 0.2%