CWE-922
Insecure Storage of Sensitive Information
ClassIncomplete
Description
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Hierarchy (View 1000)
CVEs mapped to this weakness (381)
page 20 of 20| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0881 | Med | 0.00 | 6.5 | 0.01 | Mar 9, 2022 | Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1. |
- risk 0.00cvss 6.5epss 0.01
Insecure Storage of Sensitive Information in GitHub repository chocobozzz/peertube prior to 4.1.1.