VYPR

CWE-922

Insecure Storage of Sensitive Information

ClassIncomplete

Description

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.

Hierarchy (View 1000)

Parents

CVEs mapped to this weakness (381)

page 20 of 20
  • CVE-2022-0881MedMar 9, 2022
    risk 0.00cvss 6.5epss 0.01

    Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.