Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2016-9593MEDIUMforeman-debug before version 1.15.0 is vulnerable to a flaw in foreman-debug's logging. An attacker with access to the foreman log file woulEPSS 1.0%CVE-2022-29833MEDIUMInsufficiently Protected Credentials vulnerability in Mitsubishi Electric Corporation GX Works3 versions 1.015R and later allows a remote unEPSS 1.0%CVE-2020-14489MEDIUMOpenClinic GAEPSS 1.0%CVE-2024-47081MEDIUMRequests vulnerable to .netrc credentials leak via malicious URLsEPSS 1.0%CVE-2021-41300CRITICALECOA BAS controller - Insufficiently Protected Credentials-2EPSS 1.0%CVE-2022-45599CRITICALAztech WMB250AC Mesh Routers Firmware Version 016 2020 is vulnerable to PHP Type Juggling in file /var/www/login.php, allows attackers to gaEPSS 1.0%CVE-2024-51984MEDIUMAuthenticated disclosure of external service passwords via pass-back attack affecting multiple models from Brother Industries, Ltd, FUJIFILM Business Innovation, Ricoh, Toshiba Tec, and Konica Minolta, Inc.EPSS 1.0%CVE-2023-31824An issue found in DERICIA Co. Ltd, DELICIA v.13.6.1 allows a remote attacker to gain access to sensitive information via the channel access EPSS 1.0%CVE-2023-49280HIGHData leak of password hash through xwiki change requestEPSS 0.9%CVE-2025-25650CRITICALAn issue in the storage of NFC card data in Dorset DG 201 Digital Lock H5_433WBSK_v2.2_220605 allows attackers to produce cloned NFC cards tEPSS 0.9%CVE-2021-23196HIGHFresenius Kabi Agilia Connect Infusion System insufficiently protected credentialsEPSS 0.9%CVE-2021-22798A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposedEPSS 0.9%CVE-2021-33024LOWPhilips Vue PACS Insufficiently Protected CredentialsEPSS 0.9%CVE-2019-11284MEDIUMReactor Netty authentication leak in redirectsEPSS 0.9%CVE-2021-3528A flaw was found in noobaa-operator in versions before 5.7.0, where internal RPC AuthTokens between the noobaa operator and the noobaa core EPSS 0.9%CVE-2025-27648CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.913 Application 20.0.2253 allows Cross Tenant Password Exposure V-20EPSS 0.9%CVE-2025-27650CRITICALVasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.862 Application 20.0.2014 allows Private Keys in Docker Overlay V-20EPSS 0.9%CVE-2022-30601CRITICALInsufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially eEPSS 0.9%CVE-2020-36896HIGHQiHang Media Web Digital Signage 3.0.9 Cleartext Credentials DisclosureEPSS 0.9%CVE-2026-47282MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.9%