CWE-212

Improper Removal of Sensitive Information Before Storage or Transfer

Parent: CWE-669 - Incorrect Resource Transfer Between Spheres

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

115 vulnerabilities with CWE-212
CVE-2022-0536 LOW
NPM follow-redirects <1.14.8 - Info Disclosure
CVSS 2.6
CVE-2022-23605 MEDIUM
Wire Webapp <2022-01-27-production.0 - Info Disclosure
CVSS 4.4
CVE-2022-0355 HIGH
NPM simple-get <4.0.1 - Info Disclosure
CVSS 8.8
CVE-2021-46813 HIGH
Huawei EMUI and Magic UI - Sensitive Information Exposure via Residual Files in ChinaDRM Module
CVSS 7.5
CVE-2021-33082 MEDIUM
Intel(R) SSD/Optane(TM) SSD - Info Disclosure
CVSS 4.6
CVE-2021-33080 MEDIUM
Intel Optane SSD and DC Firmware - Unauthenticated Information Disclosure via Uncleared Debug Data
CVSS 6.8
CVE-2021-26341 MEDIUM
AMD Athlon X4 and Ryzen Threadripper Firmware - Information Disclosure via Transient Execution
CVSS 6.5
CVE-2021-3602 MEDIUM
Buildah < 1.16.8 - Information Disclosure via Chroot Isolation
CVSS 5.5
CVE-2021-39891 MEDIUM
GitLab CE/EE >=8.0 - Info Disclosure
CVSS 5.9
CVE-2021-38554 MEDIUM
HashiCorp Vault <1.8.0 - Info Disclosure
CVSS 5.3
CVE-2021-28689 MEDIUM
Xen < 4.12.0 - Information Disclosure via Speculative Execution in 32-bit PV Guests
CVSS 5.5
CVE-2021-32658 MEDIUM
Nextcloud Android <3.16.1 - Info Disclosure
CVSS 4.7
CVE-2021-31780 HIGH
MISP 2.4.141 - Information Disclosure via Incorrect Sharing Group Association
CVSS 7.5
CVE-2021-0340 HIGH
Android 10 - Unredacted Location Information Leak in IsoInterface.java
CVSS 8.8
CVE-2021-3031 MEDIUM
PAN-OS 8.1.0-8.1.17 - Information Exposure via Ethernet Packet Padding
CVSS 4.3
CVE-2020-36476 HIGH
Mbed TLS <2.24.0 - Memory Corruption
CVSS 7.5
CVE-2020-14301 MEDIUM
libvirt < 6.3.0 - Information Disclosure via HTTP Cookie Exposure in dumpxml Command
CVSS 6.5
CVE-2020-11198 MEDIUM
Qualcomm Firmware - Sensitive Information Exposure via Improper Memory Clearing
CVSS 6.7
CVE-2020-26965 MEDIUM
Firefox <83 & Firefox ESR <78.5 - Info Disclosure
CVSS 6.5
CVE-2020-8696 MEDIUM
Intel(R) Processors - Info Disclosure
CVSS 5.5
CVE-2020-25635 MEDIUM
Ansible < 2.10.1 - Sensitive Information Exposure via AWS SSM Connection Plugin
CVSS 5.0
CVE-2020-14370 MEDIUM
Podman < 2.0.5 - Information Disclosure via Environment Variable Leak
CVSS 5.3
CVE-2020-11684 CRITICAL
AT91bootstrap <3.9.2 - Info Disclosure
CVSS 9.1
CVE-2020-15024 MEDIUM
Avast Antivirus <20.1.5069.562 - Info Disclosure
CVSS 5.5
CVE-2020-15094 HIGH
Symfony <4.4.13, 5.1.5 - Info Disclosure
CVSS 8.0
Details
Vulnerabilities 115