VYPR

CWE-214

Invocation of Process Using Visible Sensitive Information

BaseIncomplete

Description

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the product or related resources.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (26)

page 1 of 2
  • CVE-2020-36771HigJan 22, 2024
    risk 0.51cvss 7.8epss 0.00

    CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

  • CVE-2024-4254HigJun 4, 2024
    risk 0.46cvss 7.1epss 0.00

    The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which…

  • CVE-2018-16837HigOct 23, 2018
    risk 0.44cvss 7.8epss 0.00

    Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which…

  • CVE-2025-5452MedNov 11, 2025
    risk 0.43cvss 6.6epss 0.00

    A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to…

  • CVE-2021-3859HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

  • CVE-2020-5422MedOct 2, 2020
    risk 0.42cvss 6.5epss 0.01

    BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

  • CVE-2026-33247HigMar 25, 2026
    risk 0.41cvss 7.4epss 0.00

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any…

  • CVE-2025-1333MedMay 1, 2025
    risk 0.39cvss 6.0epss 0.00

    IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose…

  • CVE-2025-32987MedApr 15, 2025
    risk 0.39cvss 6.0epss 0.00

    Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

  • CVE-2025-59955MedJan 5, 2026
    risk 0.37cvss 5.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members`…

  • CVE-2024-28799MedAug 14, 2024
    risk 0.36cvss 5.6epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of…

  • CVE-2023-25722MedMar 28, 2023
    risk 0.36cvss 5.5epss 0.00

    A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the…

  • CVE-2026-18915MedAug 6, 2026
    risk 0.33cvss 5.0epss 0.00

    Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4.

  • CVE-2026-40159MedApr 10, 2026
    risk 0.29cvss 5.5epss 0.00

    PraisonAI is a multi-agent teams system. Prior to 4.5.128, PraisonAI’s MCP (Model Context Protocol) integration allows spawning background servers via stdio using user-supplied command strings (e.g., MCP("npx -y @smithery/cli ...")). These commands are executed through…

  • CVE-2025-53860MedOct 15, 2025
    risk 0.27cvss 4.1epss 0.00

    A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not…

  • CVE-2020-1753MedMar 16, 2020
    risk 0.26cvss 5.0epss 0.01

    A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are…

  • CVE-2025-48709LowAug 7, 2025
    risk 0.25cvss 3.8epss 0.00

    BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a…

  • CVE-2024-1742LowMar 22, 2024
    risk 0.25cvss 3.8epss 0.00

    Invocation of the sqlplus command with sensitive information in the command line in the mk_oracle Checkmk agent plugin before Checkmk 2.3.0b4 (beta), 2.2.0p24, 2.1.0p41 and 2.0.0 (EOL) allows the extraction of this information from the process list.

  • CVE-2024-39314MedJul 1, 2024
    risk 0.24cvss 4.7epss 0.00

    toy-blog is a headless content management system implementation. Starting in version 0.4.3 and prior to version 0.5.0, the administrative password was leaked through the command line parameter. The problem was patched in version 0.5.0. As a workaround, pass…

  • CVE-2018-17957LowDec 26, 2018
    risk 0.22cvss 3.4epss 0.00

    The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.