CWE-319
Cleartext Transmission of Sensitive Information
Description
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-102 · CAPEC-117 · CAPEC-383 · CAPEC-477 · CAPEC-65
CVEs mapped to this weakness (950)
page 47 of 48| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-88013 | Low | 0.17 | 3.7 | 0.00 | Sep 10, 2026 | rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.go, while its fshttp.NewClient… | ||
| CVE-2025-0252 | Low | 0.17 | 2.6 | 0.00 | Jul 25, 2025 | HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit. | ||
| CVE-2021-36382 | Low | 0.17 | 2.6 | 0.01 | Jul 12, 2021 | Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext). | ||
| CVE-2022-0005 | Low | 0.16 | 2.4 | 0.00 | May 12, 2022 | Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access. | ||
| CVE-2026-25608 | Low | 0.15 | — | 0.00 | May 22, 2026 | STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5. | ||
| CVE-2025-61738 | Low | 0.15 | — | 0.00 | Dec 22, 2025 | Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network. | ||
| CVE-2025-0250 | Low | 0.14 | 2.2 | 0.00 | Jul 25, 2025 | HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks. | ||
| CVE-2024-8013 | Low | 0.14 | 2.2 | 0.00 | Oct 28, 2024 | A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue… | ||
| CVE-2026-79782 | Low | 0.13 | 3.1 | 0.00 | Aug 25, 2026 | rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers. | ||
| CVE-2023-45716 | Low | 0.11 | 1.7 | 0.00 | Feb 9, 2024 | Sametime is impacted by sensitive information passed in URL. | ||
| CVE-2024-42181 | Low | 0.10 | 1.6 | 0.00 | Jan 12, 2025 | HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | ||
| CVE-2025-54799 | Low | 0.08 | — | 0.00 | Aug 7, 2025 | Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike the http-01 challenge… | ||
| CVE-2026-48978 | Low | 0.07 | — | 0.00 | Jul 17, 2026 | oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such… | ||
| CVE-2026-3182 | Med | 0.00 | 4.3 | 0.01 | Jul 21, 2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. | ||
| CVE-2026-34346 | Med | 0.00 | 5.5 | 0.00 | Jul 14, 2026 | Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally. | ||
| CVE-2026-53624 | Med | 0.00 | 4.8 | 0.00 | Jul 8, 2026 | Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of… | ||
| CVE-2026-55844 | Hig | 0.00 | 7.5 | 0.00 | Jun 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find… | ||
| CVE-2026-0767 | 0.00 | — | 0.00 | Jan 23, 2026 | Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue.… | |||
| CVE-2024-10718 | Hig | 0.00 | 7.5 | 0.00 | Mar 20, 2025 | In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0. | ||
| CVE-2024-43432 | Med | 0.00 | 5.3 | 0.00 | Nov 11, 2024 | A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs. |
- risk 0.17cvss 3.7epss 0.00
rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.49.0 until 1.75.1, the HTTP backend attaches headers configured through --http-headers or headers= to requests in backend/http/http.go, while its fshttp.NewClient…
- risk 0.17cvss 2.6epss 0.00
HCL IEM is affected by a password in cleartext vulnerability. Sensitive information is transmitted without adequate protection, potentially exposing it to unauthorized access during transit.
- risk 0.17cvss 2.6epss 0.01
Devolutions Server before 2021.1.18, and LTS before 2020.3.20, allows attackers to intercept private keys via a man-in-the-middle attack against the connections/partial endpoint (which accepts cleartext).
- risk 0.16cvss 2.4epss 0.00
Sensitive information accessible by physical probing of JTAG interface for some Intel(R) Processors with SGX may allow an unprivileged user to potentially enable information disclosure via physical access.
- risk 0.15cvss —epss 0.00
STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middle attack and obtain sensitive data such as passwords, personal data, or authentication tokens. This issue was fixed in version 9.5.
- risk 0.15cvss —epss 0.00
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.
- risk 0.14cvss 2.2epss 0.00
HCL IEM is affected by an authorization token sent in cookie vulnerability. A token used for authentication and authorization is being handled in a manner that may increase its exposure to security risks.
- risk 0.14cvss 2.2epss 0.00
A bug in query analysis of certain complex self-referential $lookup subpipelines may result in literal values in expressions for encrypted fields to be sent to the server as plaintext instead of ciphertext. Should this occur, no documents would be returned or written. This issue…
- risk 0.13cvss 3.1epss 0.00
rclone before 1.74.4 fails to strip the X-Amz-Security-Token header when an S3 redirect changes scheme from HTTPS to HTTP on the same host. Attackers can intercept plaintext HTTP traffic to capture AWS STS session tokens sent in request headers.
- risk 0.11cvss 1.7epss 0.00
Sametime is impacted by sensitive information passed in URL.
- risk 0.10cvss 1.6epss 0.00
HCL MyXalytics is affected by a cleartext transmission of sensitive information vulnerability. The application transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
- risk 0.08cvss —epss 0.00
Let's Encrypt client and ACME library written in Go (Lego). In versions 4.25.1 and below, the github.com/go-acme/lego/v4/acme/api package (thus the lego library and the lego cli as well) don't enforce HTTPS when talking to CAs as an ACME client. Unlike the http-01 challenge…
- risk 0.07cvss —epss 0.00
oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such…
- risk 0.00cvss 4.3epss 0.01
Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability.
- risk 0.00cvss 5.5epss 0.00
Cleartext transmission of sensitive information in Windows Ancillary Function Driver for WinSock allows an authorized attacker to disclose information locally.
- risk 0.00cvss 4.8epss 0.00
Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/helmet.go never sets the Strict-Transport-Security response header even when HSTSMaxAge is configured because it checks c.Protocol() for https instead of…
- risk 0.00cvss 7.5epss 0.00
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect when to use the internal URL, but whenever the app cannot find…
- CVE-2026-0767Jan 23, 2026risk 0.00cvss —epss 0.00
Rejected reason: Open WebU's investigation showed that this describes the behavior of plain HTTP rather than a defect in the product. TLS termination is the operator's deployment decision, as it is for any backend that speaks HTTP, and not a security issue.…
- risk 0.00cvss 7.5epss 0.00
In phpipam/phpipam version 1.5.1, the Secure attribute for sensitive cookies in HTTPS sessions is not set. This could cause the user agent to send those cookies in plaintext over an HTTP session, potentially exposing sensitive information. The issue is fixed in version 1.7.0.
- risk 0.00cvss 5.3epss 0.00
A flaw was found in moodle. The cURL wrapper in Moodle strips HTTPAUTH and USERPWD headers during emulated redirects, but retains other original request headers, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.