VYPR

CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

BaseIncomplete

Description

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Hierarchy (View 1000)

Parents

Related attack patterns (CAPEC)

CAPEC-168

CVEs mapped to this weakness (130)

page 4 of 7
  • CVE-2024-29120MedJul 17, 2024
    risk 0.38cvss 5.9epss 0.00

    In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password,…

  • CVE-2021-39891MedOct 5, 2021
    risk 0.38cvss 5.9epss 0.01

    In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

  • CVE-2026-54421MedJun 14, 2026
    risk 0.37cvss 6.8epss 0.00

    In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentials). The PATCH outcome is a security issue; the POST outcome is not a security…

  • CVE-2025-59955MedJan 5, 2026
    risk 0.37cvss 5.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members`…

  • CVE-2024-56353MedDec 20, 2024
    risk 0.36cvss 5.5epss 0.00

    In JetBrains TeamCity before 2024.12 backup file exposed user credentials and session cookies

  • CVE-2024-43554MedOct 8, 2024
    risk 0.36cvss 5.5epss 0.01

    Windows Kernel-Mode Driver Information Disclosure Vulnerability

  • CVE-2021-28689MedJun 11, 2021
    risk 0.36cvss 5.5epss 0.00

    x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it to implement paravirtualisation, Xen's…

  • CVE-2020-8696MedNov 12, 2020
    risk 0.36cvss 5.5epss 0.00

    Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

  • CVE-2020-15024MedSep 10, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.

  • CVE-2020-13179MedAug 11, 2020
    risk 0.36cvss 5.5epss 0.00

    Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single…

  • CVE-2020-11740MedApr 14, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests.…

  • CVE-2005-0406MedFeb 14, 2005
    risk 0.36cvss 5.5epss 0.00

    A design flaw in image processing software that modifies JPEG images might not modify the original EXIF thumbnail, which could lead to an information leak of potentially sensitive visual information that had been removed from the main JPEG image.

  • CVE-2026-27892MedMay 18, 2026
    risk 0.35cvss 6.5epss 0.00

    FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC metadata. Any authenticated user who downloaded an image could extract the…

  • CVE-2026-43528MedMay 5, 2026
    risk 0.35cvss 6.5epss 0.00

    OpenClaw before 2026.4.14 contains a redaction bypass vulnerability that allows authenticated gateway clients to receive unredacted secrets through sourceConfig and runtimeConfig alias fields. Attackers with config read access can exploit this to obtain provider API keys,…

  • CVE-2022-25187MedFeb 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.

  • CVE-2021-38554MedAug 13, 2021
    risk 0.35cvss 5.3epss 0.01

    HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.

  • CVE-2020-3874MedFeb 27, 2020
    risk 0.35cvss 5.3epss 0.01

    An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.

  • CVE-2018-1062MedMar 6, 2018
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same storage blocks happen to be later…

  • CVE-2026-45737MedJul 15, 2026
    risk 0.34cvss 6.3epss 0.01

    Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Argo CD ServerSideDiff can expose Kubernetes Secret values embedded in the kubectl.kubernetes.io/last-applied-configuration annotation because…

  • CVE-2025-65000MedDec 18, 2025
    risk 0.34cvss 5.3epss 0.00

    SSH private keys of the "Remote alert handlers (Linux)" rule were exposed in the rule page's HTML source in Checkmk <= 2.4.0p18 and all versions of Checkmk 2.3.0. This potentially allowed unauthorized triggering of predefined alert handlers on hosts where the handler was…