Falhas do tipo CWE-549

16 resultados

Senha não mascarada no campo de entrada

O campo de entrada de senha exibe os caracteres digitados em texto plano, em vez de ocultá-los com asteriscos ou pontos. Isso expõe a senha para quem está observando a tela física ou em gravações de tela, comprometendo a confidencialidade mesmo antes de qualquer transmissão.

Exemplo

Um formulário de login web ou aplicativo mobile que tem type='text' em vez de type='password', ou uma caixa de diálogo de autenticação que não oculta o texto enquanto o usuário digita. Qualquer pessoa ao lado consegue ler a senha completa na hora.

Como mitigar

Use input type='password' em HTML, ou no seu framework/plataforma o equivalente que oculte caracteres (asteriscos ou pontos). Se há requisito de visibilidade (botão 'mostrar/ocultar senha'), implemente toggle seguro que o usuário controla, não padrão exposto.

CVE-2022-20914MEDIUMCisco Identity Services Engine Sensitive Information Disclosure VulnerabilityEPSS 0.9%CVE-2024-10122MEDIUMTopdata Inner Rep Plus WebServer Operator Details Form InnerRepPlus.html missing password field maskingEPSS 0.5%CVE-2023-49106MEDIUMMissing Password Field Masking Vulnerability in Hitachi Device ManagerEPSS 0.4%CVE-2022-1342A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching EPSS 0.4%CVE-2023-2062MEDIUMInformation Disclosure vulnerability in EtherNet/IP Configuration toolsEPSS 0.3%CVE-2025-42904MEDIUMInformation Disclosure vulnerability in Application Server ABAPEPSS 0.3%CVE-2025-13175MEDIUMInsecure Password Storage in Y Soft SafeQ 6EPSS 0.3%CVE-2023-1763MEDIUMCanon IJ Network Tool/Ver.4.7.5 and earlier (supported OS: OS X 10.9.5-macOS 13),IJ Network Tool/Ver.4.7.3 and earlier (supported OS: OS X 1EPSS 0.3%CVE-2025-31727MEDIUMJenkins AsakusaSatellite Plugin 0.1.1 and earlier stores AsakusaSatellite API keys unencrypted in job config.xml files on the Jenkins controEPSS 0.3%CVE-2025-31728MEDIUMJenkins AsakusaSatellite Plugin 0.1.1 and earlier does not mask AsakusaSatellite API keys displayed on the job configuration form, increasinEPSS 0.3%CVE-2025-4526MEDIUMDígitro NGC Explorer Configuration missing password field maskingEPSS 0.3%CVE-2025-30197LOWJenkins Zoho QEngine Plugin 1.0.29.vfa_cc23396502 and earlier does not mask the QEngine API Key form field, increasing the potential for attEPSS 0.3%CVE-2022-22550MEDIUMDell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentialEPSS 0.2%CVE-2026-3314MEDIUMMissing Password Masking in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer and Hitachi Ops Center Analyzer viewpointEPSS 0.2%CVE-2025-0148LOWZoom Jenkins Marketplace plugin - Missing Password Field MaskingEPSS 0.2%CVE-2025-64170LOWsudo-rs: Partial password reveal is possible after timeoutEPSS 0.1%