Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2020-5263MEDIUMInformation disclosure through error objectEPSS 0.9%CVE-2017-0925Gitlab Enterprise Edition version 10.1.0 is vulnerable to an insufficiently protected credential issue in the project service integration APEPSS 0.9%CVE-2023-33263HIGHIn WFTPD 3.25, usernames and password hashes are stored in an openly viewable wftpd.ini configuration file within the WFTPD directory. NOTE:EPSS 0.9%CVE-2022-4612MEDIUMClick Studios Passwordstate insufficiently protected credentialsEPSS 0.9%CVE-2014-1423MEDIUMOnline Accounts Signon daemon gives out all oauth tokens to any appEPSS 0.8%CVE-2026-48295HIGHCAI Content Credentials | Insufficiently Protected Credentials (CWE-522)EPSS 0.8%CVE-2018-16153HIGHAn issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts tEPSS 0.8%CVE-2021-27495Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.EPSS 0.8%CVE-2021-22640HIGHOvarro TBox Insufficiently Protected CredentialsEPSS 0.8%CVE-2022-41255MEDIUMJenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it canEPSS 0.8%CVE-2022-39168MEDIUMIBM Robotic Process Automation Clients are vulnerable to proxy credentials being exposed in upgrade logs. IBM X-Force ID: 235422.EPSS 0.8%CVE-2022-1666MEDIUMSecheron SEPCOS Control and Protection RelayEPSS 0.8%CVE-2024-0368HIGHHustle <= 7.8.3 - Sensitive Information Exposure via Exposed Hubspot API KeysEPSS 0.8%CVE-2026-23658HIGHAzure DevOps: msazure Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2022-22998HIGHProtecting AWS credentials stored in plaintext on My Cloud HomeEPSS 0.8%CVE-2023-25407HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have read access to administrator credentials.EPSS 0.8%CVE-2021-3513A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wroEPSS 0.8%CVE-2022-41575HIGHA credential-exposure vulnerability in the support-bundle mechanism in Gradle Enterprise 2022.3 through 2022.3.3 allows remote attackers to EPSS 0.8%CVE-2024-7813MEDIUMSourceCodester Prison Management System Profile Image insufficiently protected credentialsEPSS 0.8%CVE-2021-36783CRITICALRancher: Failure to properly sanitize credentials in cluster template answersEPSS 0.8%