VYPR

CWE-312

Cleartext Storage of Sensitive Information

BaseDraft

Description

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (848)

page 40 of 43
  • CVE-2025-67638MedDec 10, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.540 and earlier, LTS 2.528.2 and earlier does not mask build authorization tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.

  • CVE-2025-67637MedDec 10, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.540 and earlier, LTS 2.528.2 and earlier stores build authorization tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2025-54342LowNov 14, 2025
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in the Application Server of Desktop Alert PingAlert version 6.1.0.11 to 6.1.1.2. There is Exposure of Sensitive Information because of Incompatible Policies.

  • CVE-2025-31724MedApr 2, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins Cadence vManager Plugin 4.0.0-282.v5096a_c2db_275 and earlier stores Verisium Manager vAPI keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2025-27623MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.00

    Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of views via REST API or CLI, allowing attackers with View/Read permission to view encrypted values of secrets.

  • CVE-2025-27622MedMar 5, 2025
    risk 0.21cvss 4.3epss 0.01

    Jenkins 2.499 and earlier, LTS 2.492.1 and earlier does not redact encrypted values of secrets when accessing `config.xml` of agents via REST API or CLI, allowing attackers with Agent/Extended Read permission to view encrypted values of secrets.

  • CVE-2024-12079LowJan 23, 2025
    risk 0.21cvss 3.3epss 0.00

    ECOVACS robot lawnmowers store the anti-theft PIN in cleartext on the device filesystem. An attacker can steal a lawnmower, read the PIN, and reset the anti-theft mechanism.

  • CVE-2023-32982MedMay 16, 2023
    risk 0.21cvss 4.3epss 0.00

    Jenkins Ansible Plugin 204.v8191fd551eb_f and earlier stores extra variables unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.

  • CVE-2022-42931LowDec 22, 2022
    risk 0.21cvss 3.3epss 0.00

    Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

  • CVE-2022-28162LowMay 9, 2022
    risk 0.21cvss 3.3epss 0.00

    Brocade SANnav before version SANnav 2.2.0 logs the REST API Authentication token in plain text.

  • CVE-2021-37468LowJul 25, 2021
    risk 0.21cvss 3.3epss 0.00

    NCH Reflect CRM 3.01 allows local users to discover cleartext user account information by reading the configuration files.

  • CVE-2020-2177MedApr 16, 2020
    risk 0.21cvss 4.3epss 0.01

    Jenkins Copr Plugin 0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2020-6980LowMar 16, 2020
    risk 0.21cvss 3.3epss 0.00

    Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker…

  • CVE-2010-3282LowJan 9, 2020
    risk 0.21cvss 3.3epss 0.00

    389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local…

  • CVE-2019-10450LowOct 16, 2019
    risk 0.21cvss 3.3epss 0.00

    Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2025-48463LowJun 24, 2025
    risk 0.20cvss 3.1epss 0.00

    Successful exploitation of the vulnerability could allow an attacker to intercept data and conduct session hijacking on the exposed data as the vulnerable product uses unencrypted HTTP communication, potentially leading to unauthorised access or data tampering.

  • CVE-2025-4537LowMay 11, 2025
    risk 0.20cvss 3.1epss 0.00

    A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.8.9 and classified as problematic. Affected by this issue is some unknown functionality of the file ruoyi-ui/jsencrypt.js and ruoyi-ui/login.vue of the component Password Handler. The manipulation leads to cleartext…

  • CVE-2024-45744LowSep 27, 2024
    risk 0.20cvss 3.0epss 0.00

    TopQuadrant TopBraid EDG stores external credentials insecurely. An authenticated attacker with file system access can read edg-setup.properites and obtain the secret to decrypt external passwords stored in edg-vault.properties. An authenticated attacker could gain file system…

  • CVE-2018-17499LowMar 21, 2019
    risk 0.19cvss 2.9epss 0.00

    Envoy Passport for Android and Envoy Passport for iPhone could allow a local attacker to obtain sensitive information, caused by the storing of unencrypted data in logs. An attacker could exploit this vulnerability to obtain two API keys, a token and other sensitive information.

  • CVE-2018-17489LowMar 21, 2019
    risk 0.19cvss 2.9epss 0.00

    EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social…