Fallos del tipo CWE-922

278 resultados

Armazenamento inseguro de informações sensíveis

Ocorre quando dados sensíveis (senhas, tokens, chaves, dados pessoais) são armazenados sem proteção adequada — em texto plano, em cache, em arquivos acessíveis ou em memória não cifrada. Um atacante que ganha acesso ao sistema consegue recuperar essas informações diretamente, comprometendo contas, autenticação e privacidade.

Ejemplo

Uma aplicação móvel salva o token de autenticação em SharedPreferences (Android) ou UserDefaults (iOS) sem encriptação; ou um servidor escreve senhas em arquivos de log; ou credenciais ficam em variáveis de ambiente em histórico de shell — tudo recuperável por quem tiver acesso ao dispositivo ou servidor.

Cómo mitigar

Use APIs de armazenamento seguro: Keychain (iOS), Keystore (Android), DPAPI (Windows), ou cofres de secrets (Vault, AWS Secrets Manager). Nunca registre dados sensíveis em logs. Cifre dados em repouso com padrões reconhecidos (AES-256) e remova do histórico e cache tudo que não for necessário manter.

CVE-2022-1257MEDIUMImproper Verification of Cryptographic Signature by McAfee AgentEPSS 0.6%CVE-2023-6565MEDIUMInfiniteWP Client <= 1.12.3 - Unauthenticated Sensitive Information ExposureEPSS 0.6%CVE-2024-44175HIGHThis issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sequoia 15, macOS Sonoma 14.7.1. An app may be aEPSS 0.6%CVE-2023-45182HIGHIBM i Access Client Solutions information disclosureEPSS 0.6%CVE-2024-57436HIGHRuoYi v4.8.0 was discovered to allow unauthorized attackers to view the session ID of the admin in the system monitoring. This issue can allEPSS 0.6%CVE-2022-1021HIGHInsecure Storage of Sensitive Information in chatwoot/chatwootEPSS 0.6%CVE-2022-32833MEDIUMAn issue existed with the file paths used to store website data. The issue was resolved by improving how website data is stored. This issue EPSS 0.6%CVE-2024-27789MEDIUMA logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.8 and iPadOS 16.7.8, macOS Monterey 12.7.5, macOS Sonoma 1EPSS 0.6%CVE-2022-20939MEDIUMCisco Smart Software Manager On-Prem Privilege Escalation VulnerabilityEPSS 0.6%CVE-2022-41320MEDIUMVeritas System Recovery (VSR) versions 18 and 21 store a network destination password in the Windows registry during configuration of the baEPSS 0.6%CVE-2024-28069HIGHA vulnerability in the legacy chat component of Mitel MiContact Center Business through 10.0.0.4 could allow an unauthenticated attacker to EPSS 0.6%CVE-2024-57546HIGHAn issue in CMSimple v.5.16 allows a remote attacker to obtain sensitive information via a crafted script to the validate link function.EPSS 0.6%CVE-2022-2815MEDIUMInsecure Storage of Sensitive Information in publify/publifyEPSS 0.6%CVE-2024-5598HIGHAdvanced File Manager <= 5.2.4 - Sensitive Information Exposure via Directory ListingEPSS 0.6%CVE-2023-42913HIGHThis issue was addressed through improved state management. This issue is fixed in macOS Sonoma 14.2. Remote Login sessions may be able to oEPSS 0.5%CVE-2024-5599HIGHFileOrganizer <= 1.0.7 - Sensitive Information Exposure via Directory ListingEPSS 0.5%CVE-2023-22687LOWWordPress Freesoul Deactivate Plugins – Plugin manager and cleanup Plugin <= 1.9.4.0 is vulnerable to Sensitive Data ExposureEPSS 0.5%CVE-2024-22808HIGHAn issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the comEPSS 0.5%CVE-2023-45859HIGHIn Hazelcast through 4.1.10, 4.2 through 4.2.8, 5.0 through 5.0.5, 5.1 through 5.1.7, 5.2 through 5.2.4, and 5.3 through 5.3.2, some client EPSS 0.5%CVE-2024-25940MEDIUMbhyveload(8) host file accessEPSS 0.5%