Falhas do tipo CWE-798

943 resultados

Credenciais codificadas em tempo de compilação

É quando senhas, chaves de API, tokens ou outras credenciais são gravadas diretamente no código-fonte ou em arquivos de configuração sem proteção. O desenvolvedor deixa explícito no binário ou repositório dados que deveriam ser secretos, permitindo que qualquer pessoa com acesso ao código ou ao executável extraia as credenciais e acesse sistemas protegidos.

Exemplo

Um desenvolvedor coloca `const apiKey = 'sk-prod-abc123xyz'` no código JavaScript, ou deixa `<password>admin123</password>` em um arquivo XML dentro da aplicação. Um atacante ou concorrente com acesso ao repositório Git ou ao APK extraído consegue encontrar e usar essas credenciais em produção.

Como mitigar

Armazene credenciais em variáveis de ambiente, cofres de segurança (como AWS Secrets Manager, HashiCorp Vault, Azure Key Vault) ou arquivos de configuração externos não versionados. Nunca commite credenciais no repositório; use ferramentas de escaneamento de repositórios para detectar padrões de senhas antes do push.

CVE-2022-41398HIGHThe optional Global Search feature for Sage 300 through version 2022 uses a set of hard-coded credentials for the accompanying Apache Solr iEPSS 0.5%CVE-2022-45425HIGHSome Dahua software products have a vulnerability of using of hard-coded cryptographic key. An attacker can obtain the AES crypto key by expEPSS 0.5%CVE-2025-57602CRITICALInsufficient hardening of the proxyuser account in the AiKaan IoT management platform, combined with the use of a shared, hardcoded SSH privEPSS 0.5%CVE-2026-71801CRITICALAn issue was discovered in s-pms SPMS-Server through v1.0. The application contains a hardcoded default access token secret within its core EPSS 0.5%CVE-2026-56278CRITICALFlowise - Session Hijacking via Weak Default Express Session SecretEPSS 0.5%CVE-2026-22911MEDIUMFirmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unEPSS 0.5%CVE-2024-53614MEDIUMA hardcoded decryption key in Thinkware Cloud APK v4.3.46 allows attackers to access sensitive data and execute arbitrary commands with elevEPSS 0.5%CVE-2026-5189CRITICALNexus Repository 3 - Hardcoded Credential in Internal Database ComponentEPSS 0.5%CVE-2024-23685MEDIUMFOLIO mod-remote-storage Hard Coded CredentialsEPSS 0.5%CVE-2025-8857CRITICALChanging|Clinic Image System - Use of Hard-coded CredentialsEPSS 0.5%CVE-2025-51536CRITICALAustrian Archaeological Institute (AI) OpenAtlas v8.11.0 as discovered to contain a hardcoded Administrator password.EPSS 0.5%CVE-2024-39374CRITICALUse of Hard-coded Credentials in TELSAT marKoni FM TransmitterEPSS 0.5%CVE-2021-35252HIGHCommon Key Vulnerability in Serv-U FTP ServerEPSS 0.5%CVE-2025-46274CRITICALPlanet Technology Network Products Use of Hard-coded CredentialsEPSS 0.5%CVE-2025-65730HIGHAuthentication Bypass via Hardcoded Credentials GoAway up to v0.62.18, fixed in 0.62.19, uses a hardcoded secret for signing JWT tokens usedEPSS 0.5%CVE-2025-1242CRITICALAdministrative Credentials Can Be Extracted Through Gardyn API ResponsesEPSS 0.5%CVE-2024-33895MEDIUMCosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parametersEPSS 0.5%CVE-2023-4539HIGHHardcoded password in Comarch ERP XLEPSS 0.5%CVE-2024-50688CRITICALSunGrow iSolarCloud Android application V2.1.6.20241017 and prior contains hardcoded credentials. The application (regardless of the user acEPSS 0.5%CVE-2024-28778MEDIUMIBM Cognos Controller information disclosureEPSS 0.5%