VYPR

CWE-525

Use of Web Browser Cache Containing Sensitive Information

VariantIncomplete

Description

The web application does not use an appropriate caching policy that specifies the extent to which each web page and associated form fields should be cached.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-37

CVEs mapped to this weakness (33)

page 1 of 2
  • CVE-2025-15554HigMar 16, 2026
    risk 0.51cvss 7.8epss 0.00

    Browser caching of LAPS passwords in Truesec’s LAPSWebUI before version 2.4 allows an attacker with access to a workstation to escalate their privileges via disclosure of local admin passwords.

  • CVE-2025-48947HigJun 4, 2025
    risk 0.43cvss epss 0.00

    The Auth0 Next.js SDK is a library for implementing user authentication in Next.js applications. In Auth0 Next.js SDK versions 4.0.1 through 4.6.0, `__session` cookies set by auth0.middleware may be cached by CDNs due to missing Cache-Control headers. Three preconditions must be…

  • CVE-2026-27514MedFeb 23, 2026
    risk 0.42cvss 6.5epss 0.00

    Shenzhen Tenda F3 Wireless Router firmware V12.01.01.55_multi contains a sensitive information exposure vulnerability in the configuration download functionality. The configuration download response includes the router password and administrative password in plaintext. The…

  • CVE-2026-13697HigJul 29, 2026
    risk 0.41cvss 7.4epss 0.00

    undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default…

  • CVE-2025-36364MedMar 3, 2026
    risk 0.40cvss 6.2epss 0.00

    IBM DevOps Plan 3.0.0 through 3.0.5 allows web page cache to be stored locally which can be read by another user on the system.

  • CVE-2024-31906MedJan 26, 2025
    risk 0.40cvss 6.2epss 0.00

    IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2026-41918MedJun 2, 2026
    risk 0.37cvss 5.7epss 0.00

    A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applications stores sensitive information in the browser cache when an authenticated user modify specific configurations. This could allow an authenticated attacker to…

  • CVE-2026-24437MedJan 26, 2026
    risk 0.36cvss 5.5epss 0.00

    Shenzhen Tenda W30E V2 firmware versions up to and including V16.01.0.19(5037) serve sensitive administrative content without appropriate cache-control directives. As a result, browsers may store credential-bearing responses locally, exposing them to subsequent unauthorized…

  • CVE-2021-42015MedNov 9, 2021
    risk 0.36cvss 5.5epss 0.00

    A vulnerability has been identified in Mendix Applications using Mendix 7 (All versions < V7.23.26), Mendix Applications using Mendix 8 (All versions < V8.18.12), Mendix Applications using Mendix 9 (All versions < V9.6.1). Applications built with affected versions of Mendix…

  • CVE-2026-41322MedApr 24, 2026
    risk 0.34cvss 5.3epss 0.00

    @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the…

  • CVE-2020-17522MedJan 26, 2021
    risk 0.31cvss 5.8epss 0.04

    When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these…

  • CVE-2025-62276MedNov 1, 2025
    risk 0.29cvss 5.5epss 0.00

    The Document Library and the Adaptive Media modules in Liferay Portal 7.4.0 through 7.4.3.111, and older unsupported versions, and Liferay DXP 2023.Q4.0 through 2023.Q4.10, 2023.Q3.1 through 2023.Q3.10, 7.4 GA through update 92, and older unsupported versions uses an incorrect…

  • CVE-2024-25142MedJun 14, 2024
    risk 0.29cvss 5.5epss 0.00

    Use of Web Browser Cache Containing Sensitive Information vulnerability in Apache Airflow.  Airflow did not return "Cache-Control" header for dynamic content, which in case of some browsers could result in potentially storing sensitive data in local cache of the browser. This…

  • CVE-2025-36082MedSep 15, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM OpenPages 9.0 and 9.1 allows web page cache to be stored locally which can be read by another user on the system.

  • CVE-2025-1348MedJun 18, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.4 could allow a local user to obtain sensitive information from a user’s web browser cache due to not using a suitable caching policy.

  • CVE-2025-1334MedJun 3, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2023-43035MedApr 10, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM Sterling Control Center 6.2.1, 6.3.1, and 6.4.0 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2024-22349MedJan 20, 2025
    risk 0.26cvss 4.0epss 0.00

    IBM DevOps Velocity 5.0.0 and IBM UrbanCode Velocity 4.0.0 through 4.0. 25 allows web pages to be stored locally which can be read by another user on the system.

  • CVE-2022-38383MedJun 28, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Cloud Pak for Security (CP4S) 1.10.0.0 through 1.10.11.0 and IBM QRadar Software Suite 1.10.12.0 through 1.10.21.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 233673.

  • CVE-2022-43841MedMay 30, 2024
    risk 0.26cvss 4.0epss 0.00

    IBM Aspera Console 3.4.0 through 3.4.2 PL9 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 239078.