VYPR

CWE-214

Invocation of Process Using Visible Sensitive Information

BaseIncomplete

Description

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the product or related resources.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (35)

page 1 of 2
  • CVE-2020-36771HigJan 22, 2024
    risk 0.51cvss 7.8epss 0.00

    CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

  • CVE-2019-3869HigMar 28, 2019
    risk 0.47cvss 7.2epss 0.01

    When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

  • CVE-2026-76054HigAug 24, 2026
    risk 0.46cvss —epss 0.00

    Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by…

  • CVE-2024-4254HigJun 4, 2024
    risk 0.46cvss 7.1epss 0.00

    The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which…

  • CVE-2018-16837HigOct 23, 2018
    risk 0.44cvss 7.8epss 0.00

    Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which…

  • CVE-2025-5452MedNov 11, 2025
    risk 0.43cvss 6.6epss 0.00

    A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to…

  • CVE-2021-3859HigAug 26, 2022
    risk 0.42cvss 7.5epss 0.02

    A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

  • CVE-2020-5422MedOct 2, 2020
    risk 0.42cvss 6.5epss 0.01

    BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

  • CVE-2026-33247HigMar 25, 2026
    risk 0.41cvss 7.4epss 0.01

    NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any…

  • CVE-2025-1333MedMay 1, 2025
    risk 0.39cvss 6.0epss 0.00

    IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose…

  • CVE-2025-32987MedApr 15, 2025
    risk 0.39cvss 6.0epss 0.00

    Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

  • CVE-2025-59955MedJan 5, 2026
    risk 0.37cvss 5.7epss 0.00

    Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Coolify versions prior to and including v4.0.0-beta.420.8 have an information disclosure vulnerability in the `/api/v1/teams/{team_id}/members` and `/api/v1/teams/current/members`…

  • CVE-2026-92768MedSep 18, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component…

  • CVE-2026-80158MedAug 26, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the…

  • CVE-2026-65088MedAug 25, 2026
    risk 0.36cvss 5.5epss 0.00

    NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

  • CVE-2026-74873MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

  • CVE-2024-28799MedAug 14, 2024
    risk 0.36cvss 5.6epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of…

  • CVE-2023-25722MedMar 28, 2023
    risk 0.36cvss 5.5epss 0.00

    A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes the Veracode Java API Wrapper in a manner that allows local users (with OS-level access of the…

  • CVE-2026-61670MedSep 18, 2026
    risk 0.35cvss 6.5epss 0.00

    microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments accepted by…

  • CVE-2026-92747MedSep 18, 2026
    risk 0.33cvss 5.0epss 0.00

    A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py`…