VYPR

CWE-319

Cleartext Transmission of Sensitive Information

BaseDraftLikelihood: High

Description

The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65

CVEs mapped to this weakness (914)

page 45 of 46
  • CVE-2024-42181LowJan 12, 2025
    risk 0.10cvss 1.6epss 0.00

    HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.

  • CVE-2025-54799LowAug 7, 2025
    risk 0.08cvss epss 0.00

    Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike the http-01 challenge…

  • CVE-2026-48978LowJul 17, 2026
    risk 0.07cvss epss 0.00

    oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such…

  • CVE-2026-64742MedJul 27, 2026
    risk 0.00cvss 6.5epss 0.00

    This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in iOS 26.6 and iPadOS 26.6, tvOS 26.6, visionOS 26.6, watchOS 26.6. An app may be able to access sensitive user data.

  • CVE-2026-3182MedJul 21, 2026
    risk 0.00cvss 4.3epss 0.00

    Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.

  • CVE-2026-34346MedJul 14, 2026
    risk 0.00cvss 5.5epss 0.00

    Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.

  • CVE-2026-53624MedJul 8, 2026
    risk 0.00cvss 4.8epss 0.00

    Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of…

  • CVE-2025-36336MedJun 30, 2026
    risk 0.00cvss 5.9epss 0.00

    IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2025-12530MedJun 30, 2026
    risk 0.00cvss 5.9epss 0.00

    IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques.

  • CVE-2026-55844HigJun 29, 2026
    risk 0.00cvss 7.5epss 0.00

    Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find…

  • CVE-2026-49486HigJun 26, 2026
    risk 0.00cvss 7.5epss 0.00

    The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p()`, so although the control channel was TLS-protected the data channel was transmitted in cleartext. Any deployment using `FTPSHook` or…

  • CVE-2024-10718HigMar 20, 2025
    risk 0.00cvss 7.5epss 0.00

    In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.

  • CVE-2024-43432MedNov 11, 2024
    risk 0.00cvss 5.3epss 0.00

    A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

  • CVE-2024-6388MedJun 27, 2024
    risk 0.00cvss 5.9epss 0.00

    Marco Trevisan discovered that the Ubuntu Advantage Desktop Daemon, before version 1.12, leaks the Pro token to unprivileged users by passing the token as an argument in plaintext.

  • CVE-2023-51390MedDec 21, 2023
    risk 0.00cvss 6.5epss 0.00

    journalpump is a daemon that takes log messages from journald and pumps them to a given output. A logging vulnerability was found in journalpump which logs out the configuration of a service integration in plaintext to the supplied logging pipeline, including credential…

  • CVE-2023-33960HigJun 1, 2023
    risk 0.00cvss 7.5epss 0.01

    OpenProject is web-based project management software. For any OpenProject installation, a `robots.txt` file is generated through the server to denote which routes shall or shall not be accessed by crawlers. These routes contain project identifiers of all public projects in the…

  • CVE-2022-23509HigJan 9, 2023
    risk 0.00cvss 7.3epss 0.00

    Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing Kubernetes expertise. GitOps run has a local S3 bucket which it uses for synchronizing files that are later applied against a Kubernetes cluster. The…

  • CVE-2021-4258LowDec 19, 2022
    risk 0.00cvss 3.7epss 0.00

    A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The…

  • CVE-2022-39339MedNov 25, 2022
    risk 0.00cvss 4.3epss 0.00

    user_oidc is an OpenID Connect user backend for Nextcloud. In versions prior to 1.2.1 sensitive information such as the OIDC client credentials and tokens are sent in plain text of HTTP without TLS. Any malicious actor with access to monitor user traffic may have been able to…

  • CVE-2021-45100HigDec 16, 2021
    risk 0.00cvss 7.5epss 0.01

    The ksmbd server through 3.4.2, as used in the Linux kernel through 5.15.8, sometimes communicates in cleartext even though encryption has been enabled. This occurs because it sets the SMB2_GLOBAL_CAP_ENCRYPTION flag when using the SMB 3.1.1 protocol, which is a violation of the…