VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 19 of 45
  • CVE-2024-12604MedMar 10, 2025
    risk 0.42cvss 6.5epss 0.00

    Cleartext Storage of Sensitive Information in an Environment Variable, Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tapandsign Technologies Tap&Sign App allows Password Recovery Exploitation, Functionality Misuse. This issue affects Tap&Sign App:…

  • CVE-2024-55928MedJan 23, 2025
    risk 0.42cvss 6.5epss 0.00

    Xerox Workplace Suite exposes sensitive secrets in clear text, both locally and remotely. This vulnerability allows attackers to intercept or access secrets without encryption

  • CVE-2024-42451MedDec 4, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Veeam Backup & Replication allows low-privileged users to leak all saved credentials in plaintext. This is achieved by calling a series of methods over an external protocol, ultimately retrieving the credentials using a malicious setup on the attacker's side.…

  • CVE-2024-25658MedOct 1, 2024
    risk 0.42cvss 6.5epss 0.00

    Cleartext storage of passwords in Infinera TNMS (Transcend Network Management System) Server 19.10.3 allows attackers (with access to the database or exported configuration files) to obtain SNMP users' usernames and passwords in cleartext.

  • CVE-2024-28807MedSep 30, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Infinera hiT 7300 5.60.50. Cleartext storage of sensitive information in the memory of the @CT desktop management application allows guest OS administrators to obtain various users' passwords by accessing memory dumps of the desktop application.

  • CVE-2024-45391HigSep 3, 2024
    risk 0.42cvss 7.5epss 0.00

    Tina is an open-source content management system (CMS). Sites building with Tina CMS's command line interface (CLI) prior to version 1.6.2 that use a search token may be vulnerable to the search token being leaked via lock file (tina-lock.json). Administrators of Tina-enabled…

  • CVE-2024-4540HigJun 3, 2024
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly…

  • CVE-2024-31840MedMay 21, 2024
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in Italtel Embrace 1.6.4. The web application inserts cleartext passwords in the HTML source code. An authenticated user is able to edit the configuration of the email server. Once the user access the edit function, the web application fills the edit form…

  • CVE-2024-31587MedApr 19, 2024
    risk 0.42cvss 6.5epss 0.00

    SecuSTATION Camera V2.5.5.3116-S50-SMA-B20160811A and lower allows an unauthenticated attacker to download device configuration files via a crafted request.

  • CVE-2024-29956MedApr 18, 2024
    risk 0.42cvss 6.5epss 0.00

    A vulnerability in Brocade SANnav before v2.3.1 and v2.3.0a prints the Brocade SANnav password in clear text in supportsave logs when a user schedules a switch Supportsave from Brocade SANnav.

  • CVE-2023-50294MedDec 26, 2023
    risk 0.42cvss 6.5epss 0.00

    The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.

  • CVE-2015-8314HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

  • CVE-2023-47312MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.00

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.

  • CVE-2023-46653MedOct 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.

  • CVE-2023-40354MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are…

  • CVE-2023-36136MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.

  • CVE-2023-3395MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.00

    ​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The…

  • CVE-2023-24586MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product.

  • CVE-2023-30853HigApr 28, 2023
    risk 0.42cvss 7.6epss 0.00

    Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially…

  • CVE-2023-2335MedApr 27, 2023
    risk 0.42cvss 6.5epss 0.00

    Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0.