CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2023-30527 MEDIUM
Jenkins WSO2 Oauth Plugin < 1.0 - Cleartext Storage of Sensitive Information in Global Config
CVSS 4.3
CVE-2023-30523 MEDIUM
Jenkins Report Portal Plugin <= 0.5 - Cleartext Storage of Sensitive Information in Job Configuration
CVSS 4.3
CVE-2023-0005 MEDIUM
Palo Alto Networks PAN-OS - Info Disclosure
CVSS 4.1
CVE-2023-26593 HIGH
Yokogawa CENTUM and B/M9000 - Cleartext Storage of Sensitive Information
CVSS 7.8
CVE-2023-0614 MEDIUM
Samba 4.0.0-4.16.9 - Exposure of Sensitive Information via LDAP Filter Bypass
CVSS 6.5
CVE-2023-1683 MEDIUM
Xunrui CMS 4.61 - Info Disclosure
CVSS 4.3
CVE-2023-25263 MEDIUM
Stimulsoft Designer 2023.1.4-2023.1.5 - Cleartext Storage of Sensitive Information in Connection String
CVSS 5.5
CVE-2023-20059 MEDIUM
Cisco Catalyst Center < 2.3.3.7 - Authenticated Cleartext Storage of Sensitive Information via PnP Agent API
CVSS 4.3
CVE-2023-25596 MEDIUM
ClearPass Policy Manager - Cleartext Storage of Sensitive Information
CVSS 4.5
CVE-2023-23776 MEDIUM
FortiAnalyzer 6.4.0-6.4.10, 7.0.0-7.0.4, 7.2.0-7.2.1 - Sensitive Info Exposure via Heartbeat
CVSS 4.6
CVE-2023-26760 HIGH
Sme.UP ERP TOKYO V6R1M220406 - Info Disclosure
CVSS 7.5
CVE-2023-24964 MEDIUM
IBM InfoSphere Information Server 11.7 - Sensitive Information Exposure via Log Files
CVSS 6.2
CVE-2023-0690 MEDIUM
HashiCorp Boundary 0.10.0-0.11.2 - Cleartext Storage of Sensitive Information in PKI Worker Credentials
CVSS 5.0
CVE-2023-23944 LOW
Nextcloud Mail <2.2.2 - Info Disclosure
CVSS 2.0
CVE-2023-22332 MEDIUM
Pgpool-II 3.3.0-3.7.11 - Cleartext Storage of Sensitive Information
CVSS 6.5
CVE-2023-24454 MEDIUM
Jenkins TestQuality Updater Plugin <1.3 - Info Disclosure
CVSS 5.5
CVE-2023-24450 MEDIUM
Jenkins view-cloner Plugin <1.1 - Info Disclosure
CVSS 6.5
CVE-2023-24442 MEDIUM
Jenkins GitHub Pull Request Coverage Status Plugin <2.2.0 - Info Di...
CVSS 5.5
CVE-2023-24439 MEDIUM
Jenkins JIRA Pipeline Steps Plugin <2.0.165.v8846cf59f3db - Info Di...
CVSS 5.5
CVE-2023-24055 MEDIUM
KeePass < 2.53 - Cleartext Password Exposure via Export Trigger
CVSS 5.5
CVE-2022-46141 MEDIUM
SIMATIC STEP 7 (TIA Portal) < V19 - Info Disclosure
CVSS 4.2
CVE-2022-22302 MEDIUM
FortiGate/FortiAuthenticator <6.4.1/6.2.9/<6.0.13 - Info Disclosure
CVSS 5.3
CVE-2022-33159 MEDIUM
IBM Security Directory Suite VA <8.0.1.19 - Info Disclosure
CVSS 5.3
CVE-2022-48310 MEDIUM
Sophos Connect < 2.2.90 - Sensitive Key Material Exposure in Technical Support Archives
CVSS 5.5
CVE-2022-34910 MEDIUM
aremis_4_nomads < 1.5.1 - Cleartext Storage of Sensitive Information
CVSS 4.1
Details
Vulnerabilities 818