Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2025-23040MEDIUMMaliciously crafted remote URLs could lead to credential leak in GitHub DesktopEPSS 0.8%CVE-2020-5400HIGHCloud Controller logs environment variables from app manifestsEPSS 0.8%CVE-2023-41677HIGHA insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 EPSS 0.8%CVE-2021-41297HIGHECOA BAS controller - Insufficiently Protected Credentials-1EPSS 0.7%CVE-2022-30296HIGHInsufficiently protected credentials in the Intel(R) Datacenter Group Event iOS application, all versions, may allow an unauthenticated userEPSS 0.7%CVE-2020-8259Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.EPSS 0.7%CVE-2019-14840HIGHA flaw was found in the RHDM, where sensitive HTML form fields like Password has auto-complete enabled which may lead to leak of credentialsEPSS 0.7%CVE-2026-6253MEDIUMproxy credentials leak over redirect-to proxyEPSS 0.7%CVE-2020-15791MEDIUMA vulnerability has been identified in SIMATIC S7-300 CPU family (incl. related ET200 CPUs and SIPLUS variants) (All versions), SIMATIC S7-4EPSS 0.7%CVE-2024-29992MEDIUMAzure Identity Library for .NET Information Disclosure VulnerabilityEPSS 0.7%CVE-2022-43419MEDIUMJenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viEPSS 0.7%CVE-2022-23538MEDIUMUser credentials leaked to third-party service via HTTP redirect in scs-library-clientEPSS 0.7%CVE-2022-28291MEDIUMInsufficiently Protected Credentials: An authenticated user with debug privileges can retrieve stored Nessus policy credentials from the “neEPSS 0.7%CVE-2023-25413HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. The device allows unauthenticated access to Telnet and SNMP credentials.EPSS 0.7%CVE-2017-8446The Reporting feature in X-Pack in versions prior to 5.5.2 and standalone Reporting plugin versions versions prior to 2.4.6 had an impersonaEPSS 0.7%CVE-2022-45384MEDIUMJenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the JenkinEPSS 0.7%CVE-2024-57395CRITICALPassword Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrarEPSS 0.7%CVE-2022-1766Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add EPSS 0.7%CVE-2022-45392MEDIUMJenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the JenEPSS 0.7%CVE-2026-54617CRITICALGravitLauncher: Unauthenticated path traversal in LaunchServer FileServerHandlerEPSS 0.7%