Fallos del tipo CWE-256

215 resultados

Senha codificada ou armazenada em texto plano

Ocorre quando uma senha é embutida diretamente no código-fonte ou armazenada sem criptografia em arquivos de configuração, banco de dados ou logs. Qualquer pessoa com acesso ao binário, código ou infraestrutura consegue ler a credencial e comprometer a aplicação ou sistemas integrados.

Ejemplo

Um desenvolvedor escreve `conexao = mysql_connect('localhost', 'root', 'senha123')` diretamente no PHP, ou salva credenciais de API em um arquivo .env versionado no Git. Quando o repositório vaza ou alguém faz engenharia reversa do binário, as senhas são capturadas.

Cómo mitigar

Use gerenciadores de secrets (Vault, AWS Secrets Manager, Azure Key Vault), armazene hashes criptografados com sal em banco de dados, injete credenciais via variáveis de ambiente em runtime, e nunca commite chaves no repositório — mantenha-as separadas da base de código.

CVE-2025-66910MEDIUMTurms Server v0.10.0-SNAPSHOT and earlier contains a plaintext password storage vulnerability in the administrator authentication system. ThEPSS 0.2%CVE-2020-5315HIGHDell EMC Repository Manager (DRM) version 3.2 contains a plain-text password storage vulnerability. Proxy server user password is stored in EPSS 0.2%CVE-2022-22554HIGHDell EMC System Update, version 1.9.2 and prior, contain an Unprotected Storage of Credentials vulnerability. A local attacker with user priEPSS 0.2%CVE-2022-22557HIGHPowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locallEPSS 0.2%CVE-2026-28360LOWNocoDB: Plaintext Storage of Shared View PasswordsEPSS 0.2%CVE-2024-42496LOWSmart-tab Android app installed April 2023 or earlier contains an issue with plaintext storage of a password. If this vulnerability is exploEPSS 0.2%CVE-2023-44300MEDIUM Dell DM5500 5.14.0.0, contain a Plain-text Password Storage Vulnerability in the appliance. A local attacker with privileges could potentEPSS 0.2%CVE-2022-29085MEDIUMDell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certaiEPSS 0.2%CVE-2024-31899MEDIUMIBM Cognos Command Center information disclosureEPSS 0.2%CVE-2025-53671MEDIUMJenkins Nouvola DiveCloud Plugin 1.08 and earlier does not mask DiveCloud API Keys and Credentials Encryption Keys displayed on the job confEPSS 0.2%CVE-2026-57302MEDIUMJenkins FitNesse Plugin 1.36 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller, where they can be vEPSS 0.2%CVE-2026-31850MEDIUMPlaintext Storage of Credentials in Configuration Backup in Nexxt Nebula 300+EPSS 0.2%CVE-2025-36425MEDIUMIBM Db2 Information DisclosureEPSS 0.2%CVE-2024-45283MEDIUMInformation disclosure vulnerability in SAP NetWeaver AS for Java (Destination Service)EPSS 0.2%CVE-2025-43005MEDIUMInformation Disclosure vulnerability in SAP GUI for WindowsEPSS 0.2%CVE-2024-27166HIGHInsecure permissionsEPSS 0.2%CVE-2022-4308MEDIUMClear-text passwords in configuration filesEPSS 0.2%CVE-2021-3787MEDIUMA vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MEPSS 0.2%CVE-2026-21417HIGHDell CloudBoost Virtual Appliance, versions prior to 19.14.0.0, contains a Plaintext Storage of Password vulnerability. A high privileged atEPSS 0.2%CVE-2022-41732MEDIUMIBM Maximo information disclosureEPSS 0.2%