CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

115 vulnerabilities with CWE-212
CVE-2023-41967 LOW
Gallagher Controller 6000 <8.70.231204a - Info Disclosure
CVSS 2.4
CVE-2023-3006 MEDIUM
Linux Kernel - Information Disclosure via Spectre-BHB Branch History Injection
CVSS 5.5
CVE-2023-28834 LOW
Nextcloud Server <24.0.6 & 25.0.4 - Info Disclosure
CVSS 3.5
CVE-2023-1637 MEDIUM
Linux Kernel - Information Exposure via Suspend-to-RAM Resume
CVSS 5.5
CVE-2022-3460 HIGH
Octopus Server 2018.1.0-2022.3.10750 - Sensitive Information Exposure in Variable Preview
CVSS 7.5
CVE-2022-4734 HIGH
GitHub usememos/memos <0.9.1 - Info Disclosure
CVSS 8.1
CVE-2022-39393 HIGH
Wasmtime <2.0.2, <1.0.2 - Info Disclosure
CVSS 8.6
CVE-2022-0171 MEDIUM
Linux Kernel < 5.18 - Denial of Service via KVM SEV API
CVSS 5.5
CVE-2022-2818 CRITICAL
GitHub cockpit-hq/cockpit <2.2.2 - Info Disclosure
CVSS 9.8
CVE-2022-31162 HIGH
Slack Morphism <0.41.0 - Info Disclosure
CVSS 7.5
CVE-2022-29900 MEDIUM
AMD APU Firmware - Arbitrary Speculative Code Execution
CVSS 6.5
CVE-2022-33740 HIGH
Linux - Info Disclosure
CVSS 7.1
CVE-2022-31112 HIGH
parse-server < 4.10.13 - Information Exposure via LiveQuery Protected Fields
CVSS 8.2
CVE-2022-31090 HIGH
Guzzle < 6.5.8 - Sensitive Information Exposure via Redirect Authorization Header Leak
CVSS 7.7
CVE-2022-31043 HIGH
Guzzle < 6.5.7 - Sensitive Information Exposure via HTTPS to HTTP Redirect
CVSS 7.5
CVE-2022-31042 HIGH
Guzzle < 6.5.7 - Sensitive Cookie Header Exposure via Redirect Handling
CVSS 7.5
CVE-2022-1893 MEDIUM
GitHub polonel/trudesk <1.2.3 - Info Disclosure
CVSS 4.6
CVE-2022-30618 HIGH
Strapi 3.0.0-3.6.9 and 4.0.0-4.1.8 - Authenticated Sensitive Data Exposure via Admin Panel Relationships
CVSS 7.5
CVE-2022-30617 HIGH
Strapi 3.0.0-3.6.9 and <4.0.0-beta.15 - Authenticated Sensitive Information Exposure via Admin Panel Relationships
CVSS 8.8
CVE-2022-1650 HIGH
GitHub eventsource <2.0.2 - Info Disclosure
CVSS 8.1
CVE-2022-24798 HIGH
Internet Routing Registry daemon <4 - Info Disclosure
CVSS 7.5
CVE-2022-24719 LOW
Fluture-Node 4.0.0/1 - Info Disclosure
CVSS 2.6
CVE-2022-25187 MEDIUM
Jenkins Support Core Plugin <2.79 - Info Disclosure
CVSS 6.5
CVE-2022-23633 HIGH
Rails 5.0.0-5.2.6.1 - Information Disclosure via Thread Local State Leak
CVSS 7.4
CVE-2022-22779 LOW
Keybase Clients <5.9.0 - Info Disclosure
CVSS 3.7
Details
Vulnerabilities 115