CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (848)
page 21 of 43| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-28917 | Med | 0.42 | 6.5 | 0.01 | Nov 18, 2020 | An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext… | ||
| CVE-2020-4619 | Med | 0.42 | 6.5 | 0.01 | Sep 22, 2020 | IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976. | ||
| CVE-2020-17495 | Hig | 0.42 | 7.5 | 0.01 | Aug 11, 2020 | django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database. | ||
| CVE-2019-13021 | Med | 0.42 | 6.5 | 0.01 | May 14, 2020 | The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has… | ||
| CVE-2020-2164 | Med | 0.42 | 6.5 | 0.01 | Mar 25, 2020 | Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system. | ||
| CVE-2019-16062 | Med | 0.42 | 6.5 | 0.01 | Mar 19, 2020 | NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data. | ||
| CVE-2019-10682 | Hig | 0.42 | 7.5 | 0.01 | Mar 18, 2020 | django-nopassword before 5.0.0 stores cleartext secrets in the database. | ||
| CVE-2019-14886 | Med | 0.42 | 6.5 | 0.00 | Mar 5, 2020 | A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could… | ||
| CVE-2020-6794 | Med | 0.42 | 6.5 | 0.01 | Mar 2, 2020 | If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.… | ||
| CVE-2019-19314 | Hig | 0.42 | 7.5 | 0.01 | Jan 5, 2020 | GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext. | ||
| CVE-2016-3192 | Med | 0.42 | 6.5 | 0.01 | Nov 26, 2019 | Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files. | ||
| CVE-2019-5848 | Med | 0.42 | 6.5 | 0.00 | Nov 25, 2019 | Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | ||
| CVE-2019-15508 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2019 | In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is… | ||
| CVE-2019-15507 | Med | 0.42 | 6.5 | 0.01 | Aug 23, 2019 | In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is… | ||
| CVE-2019-3753 | Med | 0.42 | 6.5 | 0.01 | Aug 20, 2019 | Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with… | ||
| CVE-2019-13100 | Med | 0.42 | 6.5 | 0.01 | Jul 22, 2019 | The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_… | ||
| CVE-2019-13099 | Med | 0.42 | 6.5 | 0.01 | Jul 22, 2019 | The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat. | ||
| CVE-2019-5810 | Med | 0.42 | 6.5 | 0.01 | Jun 27, 2019 | Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. | ||
| CVE-2019-1627 | Med | 0.42 | 6.5 | 0.01 | Jun 20, 2019 | A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is… | ||
| CVE-2018-2028 | Med | 0.42 | 6.5 | 0.01 | Jun 6, 2019 | IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554. |
- risk 0.42cvss 6.5epss 0.01
An issue was discovered in the view_statistics (aka View frontend statistics) extension before 2.0.1 for TYPO3. It saves all GET and POST data of TYPO3 frontend requests to the database. Depending on the extensions used on a TYPO3 website, sensitive data (e.g., cleartext…
- risk 0.42cvss 6.5epss 0.01
IBM Data Risk Manager (iDNA) 2.0.6 stores user credentials in plain in clear text which can be read by an authenticated user. IBM X-Force ID: 184976.
- risk 0.42cvss 7.5epss 0.01
django-celery-results through 1.2.1 stores task results in the database. Among the data it stores are the variables passed into the tasks. The variables may contain sensitive cleartext information that does not belong unencrypted in the database.
- risk 0.42cvss 6.5epss 0.01
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has…
- risk 0.42cvss 6.5epss 0.01
Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
- risk 0.42cvss 6.5epss 0.01
NETSAS Enigma NMS 65.0.0 and prior does not encrypt sensitive data stored within the SQL database. It is possible for an attacker to expose unencrypted sensitive data.
- risk 0.42cvss 7.5epss 0.01
django-nopassword before 5.0.0 stores cleartext secrets in the database.
- risk 0.42cvss 6.5epss 0.00
A vulnerability was found in business-central, as shipped in rhdm-7.5.1 and rhpam-7.5.1, where encoded passwords are stored in errai_security_context. The encoding used for storing the passwords is Base64, not an encryption algorithm, and any recovery of these passwords could…
- risk 0.42cvss 6.5epss 0.01
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60.…
- risk 0.42cvss 7.5epss 0.01
GitLab EE 8.4 through 12.5, 12.4.3, and 12.3.6 stored several tokens in plaintext.
- risk 0.42cvss 6.5epss 0.01
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
- risk 0.42cvss 6.5epss 0.00
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- risk 0.42cvss 6.5epss 0.01
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…
- risk 0.42cvss 6.5epss 0.01
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext. This is…
- risk 0.42cvss 6.5epss 0.01
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with…
- risk 0.42cvss 6.5epss 0.01
The Send Anywhere application 9.4.18 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user via /data/data/com.estmob.android.sendanywhere/shared_prefs/sendanywhere_…
- risk 0.42cvss 6.5epss 0.01
The Momo application 2.1.9 for Android stores confidential information insecurely on the system (i.e., in cleartext), which allows a non-root user to find out the username/password of a valid user and a user's access token via Logcat.
- risk 0.42cvss 6.5epss 0.01
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
- risk 0.42cvss 6.5epss 0.01
A vulnerability in the Server Utilities of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to gain unauthorized access to sensitive user information from the configuration data that is stored on the affected system. The vulnerability is…
- risk 0.42cvss 6.5epss 0.01
IBM Maximo Asset Management 7.6 could allow a an authenticated user to replace a target page with a phishing site which could allow the attacker to obtain highly sensitive information. IBM X-Force ID: 155554.