Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2023-32191CRITICALrke's credentials are stored in the RKE1 Cluster state ConfigMapEPSS 0.7%CVE-2024-26559MEDIUMAn issue in uverif v.2.0 allows a remote attacker to obtain sensitive information.EPSS 0.7%CVE-2022-1257MEDIUMImproper Verification of Cryptographic Signature by McAfee AgentEPSS 0.6%CVE-2024-57436HIGHRuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allEPSS 0.6%CVE-2023-6565MEDIUMInfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information ExposureEPSS 0.6%CVE-2024-44175HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be aEPSS 0.6%CVE-2023-45182HIGHIBM i Access Client Solutions information disclosureEPSS 0.6%CVE-2022-32833MEDIUMAn issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue EPSS 0.6%CVE-2024-27789MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 1EPSS 0.6%CVE-2022-20939MEDIUMCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 0.6%CVE-2024-57546HIGHAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.6%CVE-2024-28069HIGHA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to EPSS 0.6%CVE-2022-2815MEDIUMInsecure Storage of Sensitive Information in publify/publifyEPSS 0.6%CVE-2024-5598HIGHAdvanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory ListingEPSS 0.6%CVE-2023-42913HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to oEPSS 0.5%CVE-2023-37879MEDIUMExposed Session Variable in Wing FTP Server <= 7.2.0EPSS 0.5%CVE-2023-45859HIGHIn Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client EPSS 0.5%CVE-2024-5599HIGHFileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory ListingEPSS 0.5%CVE-2023-22687LOWWordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-22808HIGHAn issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the comEPSS 0.5%