CWE-312
Cleartext Storage of Sensitive Information
Description
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-37
CVEs mapped to this weakness (885)
page 25 of 45| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-36158 | Med | 0.38 | 5.9 | 0.00 | Jul 5, 2021 | In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used. | ||
| CVE-2021-21339 | Med | 0.38 | 5.9 | 0.01 | Mar 23, 2021 | TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability… | ||
| CVE-2026-44940 | Med | 0.37 | 5.7 | 0.00 | Sep 17, 2026 | The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges… | ||
| CVE-2026-5224 | Med | 0.37 | 5.7 | 0.00 | Aug 18, 2026 | Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229. | ||
| CVE-2026-55885 | Med | 0.37 | 6.8 | 0.00 | Jul 10, 2026 | Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site… | ||
| CVE-2025-47147 | Med | 0.37 | 5.7 | 0.00 | Mar 3, 2026 | Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects… | ||
| CVE-2025-58401 | Med | 0.37 | 6.8 | 0.00 | Sep 5, 2025 | Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account. | ||
| CVE-2023-28912 | Med | 0.37 | 5.7 | 0.00 | Jun 28, 2025 | The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb… | ||
| CVE-2025-32752 | Med | 0.37 | 5.7 | 0.00 | May 29, 2025 | Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure. | ||
| CVE-2024-55582 | Med | 0.37 | 5.7 | 0.00 | Dec 9, 2024 | Oxide before 6 has unencrypted Control Plane datastores. | ||
| CVE-2024-21993 | Med | 0.37 | 5.7 | 0.00 | Jul 9, 2024 | SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials. | ||
| CVE-2023-27370 | Med | 0.37 | 5.7 | 0.00 | May 3, 2024 | NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit… | ||
| CVE-2023-50770 | Med | 0.37 | 6.7 | 0.00 | Dec 13, 2023 | Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that… | ||
| CVE-2023-48700 | Med | 0.37 | 5.7 | 0.00 | Nov 21, 2023 | The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to… | ||
| CVE-2023-31423 | Med | 0.37 | 5.7 | 0.00 | Aug 31, 2023 | Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected… | ||
| CVE-2021-22194 | Med | 0.37 | 5.7 | 0.00 | Mar 26, 2021 | In all versions of GitLab, marshalled session keys were being stored in Redis. | ||
| CVE-2026-80058 | Med | 0.36 | 5.5 | 0.00 | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading… | ||
| CVE-2026-73834 | Med | 0.36 | 5.5 | 0.00 | Aug 18, 2026 | A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in… | ||
| CVE-2026-61928 | Med | 0.36 | 5.5 | 0.00 | Aug 11, 2026 | Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally. | ||
| CVE-2026-34490 | Med | 0.36 | 5.5 | 0.00 | Jul 31, 2026 | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. |
- risk 0.38cvss 5.9epss 0.00
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
- risk 0.38cvss 5.9epss 0.01
TYPO3 is an open source PHP based web content management system. In TYPO3 before versions 6.2.57, 7.6.51, 8.7.40, 9.5.25, 10.4.14, 11.1.1 user session identifiers were stored in cleartext - without processing of additional cryptographic hashing algorithms. This vulnerability…
- risk 0.37cvss 5.7epss 0.00
The rancher-extension-stackstate extension in SUSE Observability exposes service tokens in plain configuration or insecure locations rather than managing them securely. An attacker with minimal access could obtain the token to gain unauthorized access or escalate privileges…
- risk 0.37cvss 5.7epss 0.00
Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve Embedded Sensitive Data. This issue affects Cryptosim: before 3.1.0.229.
- risk 0.37cvss 6.8epss 0.00
Grav is a file-based Web platform. Prior to 1.7.53, an authenticated administrator with backup permissions can download a ZIP archive containing the full Grav installation root, including user/accounts/admin.yaml with the administrator password hash and user/config with site…
- risk 0.37cvss 5.7epss 0.00
Cleartext Storage of Sensitive Information (CWE-312) in the Command Centre Mobile Client on Android and iOS could allow an attacker with access to a logged-in Operator's mobile device to extract the session token and exploit access for a limited duration. This issue affects…
- risk 0.37cvss 6.8epss 0.00
Obsidian GitHub Copilot Plugin versions prior to 1.1.7 store Github API token in cleartext form. As a result, an attacker may perform unauthorized operations on the linked Github account.
- risk 0.37cvss 5.7epss 0.00
The MIB3 unit stores the synchronized phone contact book in clear-text, allowing an attacker with either code execution privilege on the system or physical access to the system to obtain vehicle owner's contact data. The vulnerability was originally discovered in Skoda Superb…
- risk 0.37cvss 5.7epss 0.00
Dell ThinOS 2502 and prior contain a Cleartext Storage of Sensitive Information vulnerability. A high privileged attacker with physical access could potentially exploit this vulnerability, leading to Information Disclosure.
- risk 0.37cvss 5.7epss 0.00
Oxide before 6 has unencrypted Control Plane datastores.
- risk 0.37cvss 5.7epss 0.00
SnapCenter versions prior to 5.0p1 are susceptible to a vulnerability which could allow an authenticated attacker to discover plaintext credentials.
- risk 0.37cvss 5.7epss 0.00
NETGEAR RAX30 Device Configuration Cleartext Storage Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit…
- risk 0.37cvss 6.7epss 0.00
Jenkins OpenId Connect Authentication Plugin 2.6 and earlier stores a password of a local user account used as an anti-lockout feature in a recoverable format, allowing attackers with access to the Jenkins controller file system to recover the plain text password of that…
- risk 0.37cvss 5.7epss 0.00
The Nautobot Device Onboarding plugin uses the netmiko and NAPALM libraries to simplify the onboarding process of a new device into Nautobot down to, in many cases, an IP Address and a Location. Starting in version 2.0.0 and prior to version 3.0.0, credentials provided to…
- risk 0.37cvss 5.7epss 0.00
Possible information exposure through log file vulnerability where sensitive fields are recorded in the configuration log without masking on Brocade SANnav before v2.3.0 and 2.2.2a. Notes: To access the logs, the local attacker must have access to an already collected…
- risk 0.37cvss 5.7epss 0.00
In all versions of GitLab, marshalled session keys were being stored in Redis.
- risk 0.36cvss 5.5epss 0.00
Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Cleartext Storage of Sensitive Information vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading…
- risk 0.36cvss 5.5epss 0.00
A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed Secret data are collected without redaction. When an administrator runs must-gather, credentials and tokens are captured in…
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.