VYPR

CWE-526

Cleartext Storage of Sensitive Information in an Environment Variable

VariantIncomplete

Description

The product uses an environment variable to store unencrypted sensitive information.

Information stored in an environment variable can be accessible by other processes with the execution context, including child processes that dependencies are executed in, or serverless functions in cloud environments. An environment variable's contents can also be inserted into messages, headers, log files, or other outputs. Often these other dependencies have no need to use the environment variable in question. A weakness that discloses environment variables could expose this information.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (24)

page 2 of 2
  • CVE-2023-47615LowNov 9, 2023
    risk 0.21cvss 3.3epss 0.00

    A CWE-526: Exposure of Sensitive Information Through Environmental Variables vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to get…

  • CVE-2023-35931LowJun 23, 2023
    risk 0.13cvss 3.1epss 0.01

    Shescape is a simple shell escape library for JavaScript. An attacker may be able to get read-only access to environment variables. This bug has been patched in version 1.7.1.

  • CVE-2025-28381HigJun 13, 2025
    risk 0.00cvss 7.5epss 0.01

    A credential leak in OpenC3 COSMOS before v6.0.2 allows attackers to access service credentials as environment variables stored in all containers.

  • CVE-2014-2377Sep 15, 2014
    risk 0.00cvss —epss 0.02

    Ecava IntegraXor SCADA Server Stable 4.1.4360 and earlier and Beta 4.1.4392 and earlier allows remote attackers to discover full pathnames via an application tag.