CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2023-3395 MEDIUM
TWinSoft Configuration Tool - Info Disclosure
CVSS 6.5
CVE-2023-27243 HIGH
Makves DCAP <3.0.0.122 - Info Disclosure
CVSS 7.5
CVE-2023-1897 CRITICAL
Atlas Copco Power Focus 6000 - Info Disclosure
CVSS 9.4
CVE-2023-22584 HIGH
Danfoss AK-EM100 Firmware < 2.2.0.12 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-27706 HIGH
Bitwarden < 2023.4.0 - Cleartext Storage of Sensitive Biometric Keys in Windows Credential Manager
CVSS 7.1
CVE-2023-28713 HIGH
CONPROSYS HMI System <3.5.3 - Info Disclosure
CVSS 8.1
CVE-2023-28345 MEDIUM
Faronics Insight 10.0.19045 - Cleartext Storage of Sensitive Information in Teacher Console API Endpoint
CVSS 4.6
CVE-2023-32448 MEDIUM
Dell PowerPath 7.0-7.2 - Cleartext Storage of Sensitive License Key
CVSS 5.5
CVE-2023-2863 LOW
Simple Design Daily Journal 1.012.GP.B - Info Disclosure
CVSS 2.3
CVE-2023-22878 MEDIUM
IBM InfoSphere Information Server 11.7 - Cleartext Storage of Sensitive Information
CVSS 6.2
CVE-2023-32983 MEDIUM
Jenkins Ansible Plugin < 204.v8191fd551eb_f - Cleartext Storage of Sensitive Information in Configuration Form
CVSS 5.3
CVE-2023-32982 MEDIUM
Jenkins Ansible Plugin < 204.v8191fd551eb_f - Cleartext Storage of Sensitive Information in Job config.xml
CVSS 4.3
CVE-2023-20914 MEDIUM
Android 11 - Local Information Disclosure via AdminRestrictedPermissionsUtils Permissions Bypass
CVSS 5.5
CVE-2023-31408 MEDIUM
Cleartext Storage of Sensitive Information - XSS
CVSS 5.3
CVE-2023-24586 MEDIUM
SkyBridge MB-A100/110 <4.2.0 - Info Disclosure
CVSS 6.5
CVE-2023-30853 HIGH
Gradle Build Action < 2.4.2 - Exposure of Sensitive Information via GitHub Actions Cache
CVSS 7.6
CVE-2023-29471 MEDIUM
Lightbend Alpakka Kafka < 5.0.0 - Cleartext Storage of Sensitive Information in Debug Logs
CVSS 5.5
CVE-2023-2335 MEDIUM
42gears SureLock <2.40.0 - Info Disclosure
CVSS 6.5
CVE-2023-29480 HIGH
Ribose RNP < 0.16.3 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2023-31043 HIGH
EDB Postgres Advanced Server <14.6.0 - Info Disclosure
CVSS 7.5
CVE-2023-22894 MEDIUM
Strapi < 4.8.0 - Sensitive Information Exposure via Query Filter
CVSS 4.9
CVE-2023-22949 MEDIUM
TigerGraph Enterprise Free Edition 3.x - Cleartext Storage of Sensitive Information in GSQL Access Logs
CVSS 4.9
CVE-2023-30531 MEDIUM
Jenkins Consul KV Builder Plugin < 2.0.13 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2023-30530 MEDIUM
Jenkins Consul KV Builder Plugin <= 2.0.13 - Cleartext Storage of Sensitive Information
CVSS 4.3
CVE-2023-30528 MEDIUM
Jenkins WSO2 Oauth Plugin <= 1.0 - Cleartext Storage of Sensitive Information in Global Configuration Form
CVSS 6.5
Details
Vulnerabilities 818