VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (885)

page 31 of 45
  • CVE-2026-27877MedMar 27, 2026
    risk 0.35cvss 6.5epss 0.00

    When using public dashboards and direct data-sources, all direct data-sources' passwords are exposed despite not being used in dashboards. No passwords of proxied data-sources are exposed. We encourage all direct data-sources to be converted to proxied data-sources as far as…

  • CVE-2025-62261MedOct 27, 2025
    risk 0.35cvss 6.5epss 0.00

    Liferay Portal 7.4.0 through 7.4.3.99, and older unsupported versions, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 34, and older unsupported versions stores password reset tokens in plain text, which allows attackers with access…

  • CVE-2025-6224MedJul 1, 2025
    risk 0.35cvss 6.5epss 0.00

    Certificate generation in juju/utils using the cert.NewLeaf function could include private information. If this certificate were then transferred over the network in plaintext, an attacker listening on that network could sniff the certificate and trivially extract the private…

  • CVE-2024-12094MedDec 5, 2024
    risk 0.35cvss —epss 0.00

    This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of…

  • CVE-2020-11918MedNov 7, 2024
    risk 0.35cvss 5.4epss 0.00

    An issue was discovered in Siime Eye 14.1.00000001.3.330.0.0.3.14. When a backup file is created through the web interface, information on all users, including passwords, can be found in cleartext in the backup file. An attacker capable of accessing the web interface can create…

  • CVE-2024-47529MedOct 2, 2024
    risk 0.35cvss 6.5epss 0.00

    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via…

  • CVE-2023-51702MedJan 24, 2024
    risk 0.35cvss 6.5epss 0.00

    Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption.…

  • CVE-2023-46128MedOct 25, 2023
    risk 0.35cvss 6.5epss 0.01

    Nautobot is a Network Automation Platform built as a web application atop the Django Python framework with a PostgreSQL or MySQL database. In Nautobot 2.0.x, certain REST API endpoints, in combination with the `?depth=` query parameter, can expose hashed user passwords as…

  • CVE-2023-31925MedAug 31, 2023
    risk 0.35cvss 5.4epss 0.00

    Brocade SANnav before v2.3.0 and v2.2.2a stores SNMPv3 Authentication passwords in plaintext. A privileged user could retrieve these credentials with knowledge and access to these log files. SNMP credentials could be seen in SANnav SupportSave if the capture is performed…

  • CVE-2022-25187MedFeb 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.

  • CVE-2022-21818MedFeb 15, 2022
    risk 0.35cvss 5.4epss 0.00

    NVIDIA License System contains a vulnerability in the installation scripts for the DLS virtual appliance, where a user on a network after signing in to the portal can access other users’ credentials, allowing them to gain escalated privileges, resulting in limited impact to…

  • CVE-2021-41090MedDec 8, 2021
    risk 0.35cvss 6.5epss 0.01

    Grafana Agent is a telemetry collector for sending metrics, logs, and trace data to the opinionated Grafana observability stack. Prior to versions 0.20.1 and 0.21.2, inline secrets defined within a metrics instance config are exposed in plaintext over two endpoints: metrics…

  • CVE-2021-26595MedFeb 23, 2021
    risk 0.35cvss 5.3epss 0.01

    In Directus 8.x through 8.8.1, an attacker can learn sensitive information such as the version of the CMS, the PHP version used by the site, and the name of the DBMS, simply by view the result of the api-aa, called automatically upon a connection. NOTE: This vulnerability only…

  • CVE-2021-27549MedFeb 22, 2021
    risk 0.35cvss 5.3epss 0.01

    Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen

  • CVE-2021-20407MedFeb 12, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 discloses sensitive information in source code that could be used in further attacks against the system. IBM X-Force ID: 196185.

  • CVE-2020-17511MedDec 14, 2020
    risk 0.35cvss 6.5epss 0.03

    In Airflow versions prior to 1.10.13, when creating a user using airflow CLI, the password gets logged in plain text in the Log table in Airflow Metadatase. Same happened when creating a Connection with a password field.

  • CVE-2019-17655MedJun 16, 2020
    risk 0.35cvss 5.3epss 0.01

    A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the…

  • CVE-2020-12801MedMay 18, 2020
    risk 0.35cvss 5.3epss 0.01

    If LibreOffice has an encrypted document open and crashes, that document is auto-saved encrypted. On restart, LibreOffice offers to restore the document and prompts for the password to decrypt it. If the recovery is successful, and if the file format of the recovered document…

  • CVE-2020-12859MedMay 18, 2020
    risk 0.35cvss 5.3epss 0.01

    Unnecessary fields in the OpenTrace/BlueTrace protocol in COVIDSafe through v1.0.17 allow a remote attacker to identify a device model by observing cleartext payload data. This allows re-identification of devices, especially less common phone models or those in low-density…

  • CVE-2019-19291MedMar 10, 2020
    risk 0.35cvss 5.3epss 0.01

    A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log files that store login credentials in…