Falhas do tipo CWE-522

689 resultados

Credenciais Insuficientemente Protegidas

Credenciais (senhas, tokens, chaves de API) armazenadas ou transmitidas sem proteção adequada, deixando-as expostas a interceptação ou acesso não autorizado. O código falha em aplicar criptografia, hash ou controles de acesso, tornando fácil para um atacante roubar ou ler essas informações sensíveis.

Exemplo

Uma aplicação web armazena senhas em banco de dados em texto plano, ou transmite tokens de autenticação via HTTP desprotegido. Um atacante que ganhe acesso ao banco ou intercepte a rede obtém acesso imediato a todas as contas.

Como mitigar

Hash de senhas com algoritmos fortes (bcrypt, Argon2); criptografe dados sensíveis em repouso; use HTTPS obrigatório para transmissão; implemente versionamento e rotação de credenciais; evite armazenar secrets em código-fonte ou variáveis de ambiente sem proteção; use gerenciadores de segredos (HashiCorp Vault, AWS Secrets Manager).

CVE-2023-32687HIGHInsufficiently Protected ChatBot Credentials in tgstation-serverEPSS 0.6%CVE-2023-44158LOWSensitive information disclosure due to insufficient token field masking. The following products are affected: Acronis Cyber Protect 15 (LinEPSS 0.6%CVE-2024-40704MEDIUMIBM InfoSphere Information Server information disclosureEPSS 0.6%CVE-2025-0867CRITICALPrivilege Escalation in MEAC300EPSS 0.6%CVE-2022-40751MEDIUMIBM UrbanCode Deploy information disclosureEPSS 0.6%CVE-2026-62839MEDIUMMicrosoft SharePoint Server Spoofing VulnerabilityEPSS 0.6%CVE-2024-12511HIGHSMB/FTP Address Book Scan Pass-back attackEPSS 0.6%CVE-2025-54863CRITICALInsufficiently Protected Credentials in Radiometrics VizAirEPSS 0.6%CVE-2025-32963MEDIUMMinio Operator uses Kubernetes apiserver audience for AssumeRoleWithWebIdentity STSEPSS 0.6%CVE-2026-62882MEDIUMMicrosoft Outlook Spoofing VulnerabilityEPSS 0.6%CVE-2023-3251MEDIUMPass-back vulnerability in NessusEPSS 0.6%CVE-2026-81381MEDIUMGitHub Copilot and Visual Studio Code Information Disclosure VulnerabilityEPSS 0.6%CVE-2023-25191HIGHAMI MegaRAC SPX devices allow Password Disclosure through Redfish. The fixed versions are SPx_12-update-7.00 and SPx_13-update-5.00.EPSS 0.6%CVE-2022-37193HIGHChipolo ONE Bluetooth tracker (2020) Chipolo iOS app version 4.13.0 is vulnerable to Incorrect Access Control. Chipolo devices suffer from aEPSS 0.6%CVE-2024-26330MEDIUMAn issue was discovered in Kape CyberGhostVPN 8.4.3.12823 on Windows. After a successful logout, user credentials remain in memory while theEPSS 0.6%CVE-2024-6492HIGHExposure of Sensitive Information in edge browser session proxy feature in Devolutions Remote Desktop Manager 2024.2.14.0 and earlier on WinEPSS 0.6%CVE-2026-77909HIGHAzure CycleCloud Information Disclosure VulnerabilityEPSS 0.6%CVE-2024-47805HIGHJenkins Credentials Plugin 1380.va_435002fa_924 and earlier, except 1371.1373.v4eb_fa_b_7161e9, does not redact encrypted values of credentiEPSS 0.6%CVE-2019-10225A flaw was found in atomic-openshift of openshift-4.2 where the basic-user RABC role in OpenShift Container Platform doesn't sufficiently prEPSS 0.6%CVE-2022-38714MEDIUMIBM DataStage on Cloud Pak for Data information disclosureEPSS 0.6%