CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

818 vulnerabilities with CWE-312
CVE-2021-35526 MEDIUM
Hitachi ABB Power Grids System Data Manager - Info Disclosure
CVSS 6.3
CVE-2021-1865 MEDIUM
iPadOS < 14.5 - Unprotected Password Exposure in Screenshots
CVSS 5.0
CVE-2021-36096 MEDIUM
OTRS <6.0.1, 7.0.28, 8.0.15 - Info Disclosure
CVSS 5.2
CVE-2021-22929 MEDIUM
Brave Browser Desktop <1.28.62 - Info Disclosure
CVSS 6.1
CVE-2021-31989 MEDIUM
AXIS Device Manager - Info Disclosure
CVSS 5.3
CVE-2021-40087 LOW
PrimeKey EJBCA < 7.6.0 - Cleartext Storage of Sensitive Information in Audit Log
CVSS 2.7
CVE-2021-30997 HIGH
iPadOS < 15.2 - S/MIME Encrypted Email Plaintext Exposure
CVSS 7.5
CVE-2021-31820 HIGH
Octopus Server 2018.8.2-2020.6.5310 - Cleartext Storage of Sensitive Information in Web Request Proxy Configuration
CVSS 7.5
CVE-2021-37548 HIGH
JetBrains TeamCity < 2021.1 - Cleartext Storage of Sensitive Information in VCS
CVSS 7.5
CVE-2021-33325 MEDIUM
Liferay Portal <7.3.2 - Info Disclosure
CVSS 4.9
CVE-2021-33323 HIGH
Liferay Portal/DXP <7.3.2/7.1 - Info Disclosure
CVSS 7.5
CVE-2021-37468 LOW
NCH Reflect CRM < 3.01 - Cleartext Storage of Sensitive Information in Configuration Files
CVSS 3.3
CVE-2021-37452 MEDIUM
NCH Quorum < 2.03 - Cleartext Storage of Sensitive Information in Local Configuration Files
CVSS 5.5
CVE-2021-31581 HIGH
Akkadianlabs Ova Appliance < 3.0 - Improper Privilege Management
CVSS 7.9
CVE-2021-20510 MEDIUM
IBM Security Verify Access Docker 10.0.0 - Info Disclosure
CVSS 4.4
CVE-2021-31817 HIGH
Octopus Server 2020.6.0-2020.6.5146 - Cleartext Storage of Sensitive Information in Log File
CVSS 7.5
CVE-2021-31816 HIGH
Octopus Server < 2020.6.5146 - Cleartext Storage of Sensitive Information in Log File
CVSS 7.5
CVE-2021-36158 MEDIUM
Alpine Linux aports < 3.14 - Cleartext Storage of Sensitive Information in xrdp Package
CVSS 5.9
CVE-2021-29481 MEDIUM
Ratpack < 1.9.0 - Cleartext Storage of Sensitive Information in Client-Side Session Cookies
CVSS 6.5
CVE-2021-29956 MEDIUM
Thunderbird 78.8.1-78.10.1 - Cleartext Storage of OpenPGP Secret Keys
CVSS 4.3
CVE-2021-29954 CRITICAL
Hubs Cloud Reticulum < 1.0.1 - Cleartext Storage of Sensitive Information
CVSS 9.8
CVE-2021-29950 HIGH
Thunderbird < 78.8.1 - Cleartext Storage of Sensitive OpenPGP Key in Memory
CVSS 7.5
CVE-2021-27487 MEDIUM
ZOLL Defibrillator Dashboard <2.2 - Info Disclosure
CVSS 5.5
CVE-2021-28858 MEDIUM
TP-Link TL-WPA4220 4.0.2 Build 20180308 Rel.37064 - Cleartext Transmission of Sensitive Information
CVSS 5.5
CVE-2021-23211 MEDIUM
Gallagher Command Centre <8.40.1888 - Info Disclosure
CVSS 6.0
Details
Vulnerabilities 818