CWE-922
Insecure Storage of Sensitive Information
ClassIncomplete
Description
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Hierarchy (View 1000)
CVEs mapped to this weakness (383)
page 20 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-1044 | Med | 0.00 | 6.5 | 0.01 | May 12, 2022 | Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1. | ||
| CVE-2021-46440 | Hig | 0.00 | 7.5 | 0.03 | May 3, 2022 | Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext… | ||
| CVE-2022-0881 | Med | 0.00 | 6.5 | 0.01 | Mar 9, 2022 | Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. |
- risk 0.00cvss 6.5epss 0.01
Sensitive Data Exposure Due To Insecure Storage Of Profile Image in GitHub repository polonel/trudesk prior to v1.2.1.
- risk 0.00cvss 7.5epss 0.03
Storing passwords in a recoverable format in the DOCUMENTATION plugin component of Strapi before 3.6.9 and 4.x before 4.1.5 allows an attacker to access a victim's HTTP request, get the victim's cookie, perform a base64 decode on the victim's cookie, and obtain a cleartext…
- risk 0.00cvss 6.5epss 0.01
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.