VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 19 of 43
  • CVE-2015-8314HigDec 12, 2023
    risk 0.42cvss 7.5epss 0.01

    The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.

  • CVE-2023-47312MedNov 22, 2023
    risk 0.42cvss 6.5epss 0.00

    Headwind MDM Web panel 5.22.1 is vulnerable to Incorrect Access Control due to Login Credential Leakage via Audit Entries.

  • CVE-2023-46653MedOct 25, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins lambdatest-automation Plugin 1.20.10 and earlier logs LAMBDATEST Credentials access token at the INFO level, potentially resulting in its exposure.

  • CVE-2023-40354MedAug 14, 2023
    risk 0.42cvss 6.5epss 0.00

    An issue was discovered in MariaDB MaxScale before 23.02.3. A user enters an encrypted password on a "maxctrl create service" command line, but this password is then stored in cleartext in the resulting .cnf file under /var/lib/maxscale/maxscale.cnf.d. The fixed versions are…

  • CVE-2023-36136MedAug 8, 2023
    risk 0.42cvss 6.5epss 0.00

    PHPJabbers Class Scheduling System 1.0 lacks encryption on the password when editing a user account (update user page) allowing an attacker to capture all user names and passwords in clear text.

  • CVE-2023-3395MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.00

    ​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The…

  • CVE-2023-24586MedMay 10, 2023
    risk 0.42cvss 6.5epss 0.01

    Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product.

  • CVE-2023-30853HigApr 28, 2023
    risk 0.42cvss 7.6epss 0.00

    Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially…

  • CVE-2023-2335MedApr 27, 2023
    risk 0.42cvss 6.5epss 0.00

    Plaintext Password in Registry vulnerability in 42gears surelock windows surelockwinsetupv2.40.0.Exe on Windows (Registery modules) allows Retrieve Admin user credentials This issue affects surelock windows: from 2.3.12 through 2.40.0.

  • CVE-2023-30531MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins Consul KV Builder Plugin 2.0.13 and earlier does not mask the HashiCorp Consul ACL Token on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2023-30528MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.00

    Jenkins WSO2 Oauth Plugin 1.0 and earlier does not mask the WSO2 Oauth client secret on the global configuration form, increasing the potential for attackers to observe and capture it.

  • CVE-2023-0614MedApr 3, 2023
    risk 0.42cvss 6.5epss 0.01

    The fix in 4.6.16, 4.7.9, 4.8.4 and 4.9.7 for CVE-2018-10919 Confidential attribute disclosure vi LDAP filters was insufficient and an attacker may be able to obtain confidential BitLocker recovery keys from a Samba AD DC.

  • CVE-2022-31405MedFeb 27, 2023
    risk 0.42cvss 6.5epss 0.01

    MV iDigital Clinic Enterprise (iDCE) 1.0 stores passwords in cleartext.

  • CVE-2022-44644MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.01

    In Apache Linkis <=1.3.0 when used with the MySQL Connector/J in the data source module, an authenticated attacker could read arbitrary local files by connecting a rogue MySQL server, By adding allowLoadLocalInfile to true in the JDBC parameter. Therefore, the parameters in the…

  • CVE-2022-45897MedJan 31, 2023
    risk 0.42cvss 6.5epss 0.00

    On Xerox WorkCentre 3550 25.003.03.000 devices, an authenticated attacker can view the SMB server settings and can obtain the stored cleartext credentials associated with those settings.

  • CVE-2023-22332MedJan 30, 2023
    risk 0.42cvss 6.5epss 0.01

    Information disclosure vulnerability exists in Pgpool-II 4.4.0 to 4.4.1 (4.4 series), 4.3.0 to 4.3.4 (4.3 series), 4.2.0 to 4.2.11 (4.2 series), 4.1.0 to 4.1.14 (4.1 series), 4.0.0 to 4.0.21 (4.0 series), All versions of 3.7 series, All versions of 3.6 series, All versions of…

  • CVE-2023-24450MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-45439MedJan 17, 2023
    risk 0.42cvss 6.5epss 0.00

    A pair of spare WiFi credentials is stored in the configuration file of the Zyxel AX7501-B0 firmware prior to V5.17(ABPC.3)C0 in cleartext. An unauthenticated attacker could use the credentials to access the WLAN service if the configuration file has been retrieved from the…

  • CVE-2022-34339MedNov 3, 2022
    risk 0.42cvss 6.5epss 0.00

    "IBM Cognos Analytics 11.2.1, 11.2.0, 11.1.7 stores user credentials in plain clear text which can be read by an authenticated user. IBM X-Force ID: 229963."

  • CVE-2022-2805MedOct 19, 2022
    risk 0.42cvss 6.5epss 0.00

    A flaw was found in ovirt-engine, which leads to the logging of plaintext passwords in the log file when using otapi-style. This flaw allows an attacker with sufficient privileges to read the log file, leading to confidentiality loss.