Falhas do tipo CWE-522

691 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2023-26221MEDIUMTIBCO Spotfire Insufficiently Protected Credential vulnerabilityEPSS 0.2%CVE-2025-53671MEDIUMJenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job confEPSS 0.2%CVE-2026-28714MEDIUMUnnecessary transmission of sensitive cryptographic material. The following products are affected: Acronis Cyber Protect 17 (Linux, Windows)EPSS 0.2%CVE-2025-6227LOWInvite token is used as part of the secure communicationEPSS 0.2%CVE-2025-58742HIGHInsufficient Configuration Protections Enable Database Credential Interception in Milner ImageDirector CaptureEPSS 0.2%CVE-2021-27785LOWHCL Commerce could allow a local attacker to obtain sensitive personal information (CVE-2021-27785)EPSS 0.2%CVE-2025-2908HIGHInsufficiently Protected Credentials vulnerability in MeetMe productsEPSS 0.2%CVE-2024-29216MEDIUMExposed IOCTL with insufficient access control issue exists in cg6kwin2k.sys prior to 2.1.7.0. By sending a specific IOCTL request, a user wEPSS 0.2%CVE-2025-0760LOWStored Credential Disclosure VulnerabilityEPSS 0.2%CVE-2026-48022MEDIUM@hapi/wreck: Sensitive credential headers leak across cross-port and cross-scheme redirectsEPSS 0.2%CVE-2026-1966LOWYugabyteDB Anywhere Exposes LDAP Credentials in Cleartext in Web UIEPSS 0.2%CVE-2023-28088HIGHAn HPE OneView appliance dump may expose SAN switch administrative credentialsEPSS 0.2%CVE-2026-32606HIGHIncusOS has a LUKS encryption bypass due to insufficient TPM policyEPSS 0.2%CVE-2023-43634HIGH Config Partition Not Protected by Measured BootEPSS 0.2%CVE-2023-43631HIGHSSH as Root Unlockable Without Triggering Measured BootEPSS 0.2%CVE-2023-28086MEDIUMAn HPE OneView appliance dump may expose proxy credential settingsEPSS 0.2%CVE-2023-28087MEDIUMAn HPE OneView appliance dump may expose OneView user accountsEPSS 0.2%CVE-2025-2311CRITICALAuthentication Bypass in Sechard Information Technologies' SecHardEPSS 0.2%CVE-2023-28090MEDIUMAn HPE OneView appliance dump may expose SNMPv3 read credentialsEPSS 0.2%CVE-2023-28089HIGHAn HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect ModulesEPSS 0.2%