VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (886)

page 38 of 45
  • CVE-2026-76380MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 5.1.3 of the CrowdStrike OAuth API app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive document password by invoking either the detonate file or detonate url action, because the action's document_password…

  • CVE-2026-76379MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.2.1 of the Cisco Webex app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive meeting password by invoking the schedule meeting action, because the action's password parameter is not masked and is shown in…

  • CVE-2026-76378MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.4.5 of the Cisco Secure Malware Analytics app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive sample password by invoking the detonate file action, because the action's sample_password parameter is not masked…

  • CVE-2026-76377MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.5.3 of the Azure AD Graph app for Splunk SOAR, a user who holds a role with permission to run actions could expose a sensitive password by invoking the reset password action, because the action's temp_password parameter is not masked and is shown in cleartext…

  • CVE-2026-76376MedAug 19, 2026
    risk 0.28cvss 4.3epss 0.00

    In versions below 2.1.9 of the AWS IAM app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive AWS credentials by invoking an action that accepts the credentials parameter, because the parameter is not masked and is shown in cleartext…

  • CVE-2026-55985MedJul 24, 2026
    risk 0.28cvss 4.3epss 0.00

    The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext on a certain configuration page accessible to authenticated users. Any party with access to the administrative dashboard can immediately read these…

  • CVE-2026-6796MedApr 21, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword…

  • CVE-2026-33004MedMar 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins LoadNinja Plugin 2.1 and earlier does not mask LoadNinja API keys displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2026-33003MedMar 18, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins LoadNinja Plugin 2.1 and earlier stores LoadNinja API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-59450MedOct 6, 2025
    risk 0.28cvss 4.3epss 0.00

    The YoSmart YoLink Smart Hub firmware 0382 is unencrypted, and data extracted from it can be used to determine network access credentials.

  • CVE-2024-49800MedFeb 6, 2025
    risk 0.28cvss 4.3epss 0.00

    IBM ApplinX 11.1 stores sensitive information in cleartext in memory that could be obtained by an authenticated user.

  • CVE-2025-0142MedJan 30, 2025
    risk 0.28cvss 4.3epss 0.00

    Cleartext storage of sensitive information in the Zoom Jenkins Marketplace plugin before version 1.4 may allow an authenticated user to conduct a disclosure of information via network access.

  • CVE-2024-54127MedDec 5, 2024
    risk 0.28cvss —epss 0.00

    This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this…

  • CVE-2024-11159MedNov 13, 2024
    risk 0.28cvss 4.3epss 0.00

    Using remote content in OpenPGP encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird < 128.4.3 and Thunderbird < 132.0.1.

  • CVE-2024-32939MedAug 22, 2024
    risk 0.28cvss 4.3epss 0.00

    Mattermost versions 9.9.x <= 9.9.1, 9.5.x <= 9.5.7, 9.10.x <= 9.10.0, 9.8.x <= 9.8.2, when shared channels are enabled, fail to redact remote users' original email addresses stored in user props when email addresses are otherwise configured not to be visible in the local server."

  • CVE-2024-36589MedJun 13, 2024
    risk 0.28cvss 4.3epss 0.00

    An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.

  • CVE-2023-50777MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2023-50776MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2023-50773MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2023-50772MedDec 13, 2023
    risk 0.28cvss 4.3epss 0.00

    Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.