Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2023-32268HIGHAdministrator equivalent Filr user can access proxy administrator credentialsEPSS 0.7%CVE-2022-0862LOWePO password change vulnerabilityEPSS 0.7%CVE-2020-8339MEDIUMA cross-site scripting inclusion (XSSI) vulnerability was reported in the legacy IBM BladeCenter Advanced Management Module (AMM) web interfEPSS 0.7%CVE-2022-31044HIGHPlaintext Storage of Keys and Passwords in Rundeck and PagerDuty Process AutomationEPSS 0.7%CVE-2025-14524MEDIUMbearer token leak on cross-protocol redirectEPSS 0.7%CVE-2025-34207HIGHVasion Print (formerly PrinterLogic) Insecure SSH Client ConfigurationEPSS 0.7%CVE-2025-34078HIGHNSClient++ 0.5.2.35 Local Privilege Escalation via ExternalScripts and Web InterfaceEPSS 0.7%CVE-2024-28110HIGHGo SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentialsEPSS 0.7%CVE-2023-40173HIGHUnsalted passwords in fobybus/social-media-skeletonEPSS 0.7%CVE-2024-7389HIGHForminator <= 1.29.1 - HubSpot Developer API Key Sensitive Information ExposureEPSS 0.7%CVE-2026-56843CRITICALIncorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domaiEPSS 0.7%CVE-2020-5404MEDIUMAuthentication Leak On Redirect With Reactor Netty HttpClientEPSS 0.7%CVE-2025-3079MEDIUMA passback vulnerability which relates to office/small office multifunction printers and laser printers.EPSS 0.7%CVE-2025-3078MEDIUMA passback vulnerability which relates to production printers and office multifunction printers.EPSS 0.7%CVE-2023-26567HIGHSangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of gloEPSS 0.6%CVE-2023-6254HIGHPassword is send back to clientEPSS 0.6%CVE-2022-48433MEDIUMIn JetBrains IntelliJ IDEA before 2023.1 the NTLM hash could leak through an API method used in the IntelliJ IDEA built-in web server.EPSS 0.6%CVE-2023-37362HIGHWeintek Weincloud Improper AuthenticationEPSS 0.6%CVE-2026-62327CRITICAL9Router 0.4.41 - Unauthenticated API Key Exposure via /api/usage/statsEPSS 0.6%CVE-2023-20965CRITICALIn processMessageImpl of ClientModeImpl.java, there is a possible credential disclosure in the TOFU flow due to a logic error in the code. TEPSS 0.6%