Falhas do tipo CWE-922

283 resultados

Armazenamento inseguro de informações sensíveis

A aplicação armazena dados sensíveis (senhas, tokens, chaves, PII) em locais acessíveis sem proteção adequada — memória não criptografada, logs, cache, arquivos de configuração ou banco de dados sem cifra. Um atacante com acesso ao sistema de arquivos, memória ou backups consegue ler essas informações diretamente.

Exemplo

Uma app de e-commerce salva números de cartão de crédito em texto plano em um arquivo SQLite local no dispositivo móvel. Um usuário com acesso físico ao telefone, malware ou análise forense do aparelho consegue extrair os cartões intactos. Outro caso comum: API que registra em log toda requisição incluindo o Bearer token do usuário.

Como mitigar

Criptografe dados sensíveis em repouso (AES-256 para arquivos, TDE para BD). Nunca armazene senhas — use hash + salt (PBKDF2, bcrypt, Argon2). Remova dados sensíveis de logs e memória assim que desnecessários. Para mobile, use Keychain (iOS) ou Keystore (Android). Revise configurações, backups e caches periodicamente.

CVE-2024-39775MEDIUMNet Manager has an out-of-bounds read permission bypass vulnerabilityEPSS 0.4%CVE-2024-48770HIGHAn issue in Plug n Play Camera com.wisdomcity.zwave 1.1.0 allows a remote attacker to obtain sensitive information via the firmware update pEPSS 0.4%CVE-2024-23241MEDIUMThis issue was addressed through improved state management. This issue is fixed in iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4. AEPSS 0.4%CVE-2024-3723MEDIUMAdvanced Contact form 7 DB <= 2.0.2 - Sensitive Information ExposureEPSS 0.4%CVE-2023-42823LOWThe issue was resolved by sanitizing logging This issue is fixed in watchOS 10.1, macOS Sonoma 14.1, tvOS 17.1, macOS Monterey 12.7.1, iOS 1EPSS 0.4%CVE-2024-5288MEDIUMSafe-error attack on TLS 1.3 ProtocolEPSS 0.4%CVE-2024-38453HIGHThe Avalara for Salesforce CPQ app before 7.0 for Salesforce allows attackers to read an API key. NOTE: the current version is 11 as of mid-EPSS 0.4%CVE-2024-39459MEDIUMIn rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoEPSS 0.4%CVE-2023-5879MEDIUMAladdin Connect Android Application Insecure StorageEPSS 0.4%CVE-2024-3501CRITICALExposure of Sensitive Information in lunary-ai/lunaryEPSS 0.4%CVE-2024-29965MEDIUMInsecure backupEPSS 0.4%CVE-2019-5625LOWEaton Halo Home Android App Insecure StorageEPSS 0.4%CVE-2024-32236LOWAn issue in CmsEasy v.7.7 and before allows a remote attacker to obtain sensitive information via the update function in the index.php compoEPSS 0.4%CVE-2025-46627HIGHUse of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculaEPSS 0.4%CVE-2023-29755HIGHAn issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the SharedPrEPSS 0.4%CVE-2023-29757HIGHAn issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating thEPSS 0.4%CVE-2021-25406Information exposure vulnerability in Gear S Plugin prior to version 2.2.05.20122441 allows unstrusted applications to access connected BT dEPSS 0.4%CVE-2024-47043HIGHRuijie Reyee OS Insecure Storage of Sensitive InformationEPSS 0.4%CVE-2024-39339HIGHA vulnerability has been discovered in all versions of Smartplay headunits, which are widely used in Suzuki and Toyota cars. This misconfiguEPSS 0.4%CVE-2024-48783MEDIUMAn issue in Ruijie NBR3000D-E Gateway allows a remote attacker to obtain sensitive information via the /tool/shell/postgresql.conf componentEPSS 0.4%