VYPR

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

BaseIncomplete

Description

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-168

CVEs mapped to this weakness (122)

page 1 of 7
  • CVE-2026-39937HigApr 7, 2026
    risk 0.57cvss epss 0.00

    Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure. The issue has been remediated on the `master` branch, and in the release branches for MediaWiki…

  • CVE-2022-2818CriAug 15, 2022
    risk 0.57cvss 9.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.

  • CVE-2022-30617HigMay 19, 2022
    risk 0.57cvss 8.8epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content accessible to the authenticated user. For…

  • CVE-2021-0340HigFeb 10, 2021
    risk 0.57cvss 8.8epss 0.02

    In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for…

  • CVE-2019-13402HigJul 8, 2019
    risk 0.57cvss 8.8epss 0.02

    /usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of services is reset.

  • CVE-2026-42880CriMay 7, 2026
    risk 0.55cvss 9.6epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From versions 3.2.0 to before 3.2.11 and 3.3.0 to before 3.3.9, there is a missing authorization and data-masking gap in Argo CD's ServerSideDiff endpoint that allows an attacker with read-only access to…

  • CVE-2019-11243HigApr 22, 2019
    risk 0.53cvss 8.1epss 0.01

    In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions, rest.AnonymousClientConfig() did not…

  • CVE-2024-43384HigMay 7, 2026
    risk 0.52cvss 8.0epss 0.00

    A low privileged remote attacker can gain the root password due to improper removal of sensitive information before storage or transfer.

  • CVE-2026-32891CriMar 20, 2026
    risk 0.52cvss 9.0epss 0.00

    Anchorr is a Discord bot for requesting movies and TV shows and receiving notifications when items are added to a media server. Versions 1.4.1 and below contain a stored XSS vulnerability in the Jellyseerr user selector. Jellyseerr allows any account holder to execute arbitrary…

  • CVE-2022-0355HigJan 26, 2022
    risk 0.50cvss 8.8epss 0.02

    Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.

  • CVE-2026-27640HigFeb 25, 2026
    risk 0.49cvss 7.5epss 0.00

    tfplan2md is software for converting Terraform plan JSON files into human-readable Markdown reports. Prior to version 1.26.1, a bug in tfplan2md affected several distinct rendering paths: AzApi resource body properties, AzureDevOps variable groups, Scriban template context…

  • CVE-2024-8474HigJan 6, 2025
    risk 0.49cvss 7.5epss 0.01

    OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic

  • CVE-2023-52376HigFeb 18, 2024
    risk 0.49cvss 7.5epss 0.00

    Information management vulnerability in the Gallery module.Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2022-3460HigJan 3, 2023
    risk 0.49cvss 7.5epss 0.01

    In affected versions of Octopus Deploy it is possible for certain types of sensitive variables to inadvertently become unmasked when viewed in variable preview.

  • CVE-2022-39393HigNov 10, 2022
    risk 0.49cvss 8.6epss 0.01

    Wasmtime is a standalone runtime for WebAssembly. Prior to versions 2.0.2 and 1.0.2, there is a bug in Wasmtime's implementation of its pooling instance allocator where when a linear memory is reused for another instance the initial heap snapshot of the prior instance can be…

  • CVE-2021-46813HigJun 13, 2022
    risk 0.49cvss 7.5epss 0.01

    Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.

  • CVE-2022-30618HigMay 19, 2022
    risk 0.49cvss 7.5epss 0.01

    An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API users (from:users-permissions). There are…

  • CVE-2021-31780HigApr 23, 2021
    risk 0.49cvss 7.5epss 0.01

    In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignored and instead the passed local ID is…

  • CVE-2019-20637HigApr 8, 2020
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This sometimes causes information to be…

  • CVE-2020-1940HigJan 28, 2020
    risk 0.49cvss 7.5epss 0.05

    The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an additional attribute to the credentials…