CWE-312

Cleartext Storage of Sensitive Information

Parent: CWE-311 - Missing Encryption of Sensitive Data

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

805 vulnerabilities with CWE-312
CVE-2019-13021 MEDIUM
jetstream jetselect - Cleartext Storage of Sensitive Information in Installation Script
CVSS 6.5
CVE-2019-18868 CRITICAL
Blaauw Remote Kiln Control <v3.00r4 - Info Disclosure
CVSS 9.8
CVE-2019-16062 MEDIUM
NETSAS Enigma NMS <65.0.0 - Info Disclosure
CVSS 6.5
CVE-2019-10682 HIGH
django-nopassword < 5.0.0 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2019-9104 HIGH
Moxa MB3170, MB3270, MB3180, MB3280, MB3480, MB3660 Firmware - Insufficiently Protected Credentials
CVSS 7.5
CVE-2019-19291 MEDIUM
Control Center Server <1.5.0 - Info Disclosure
CVSS 5.3
CVE-2019-14886 MEDIUM
Red Hat Decision Manager and Process Automation Manager - Cleartext Storage of Sensitive Information in Security Context
CVSS 6.5
CVE-2019-18238 HIGH
Moxa ioLogik 2500 Series Firmware < 3.0 - Cleartext Storage of Sensitive Information
CVSS 7.5
CVE-2019-19314 HIGH
GitLab EE <12.5-12.3.6 - Info Disclosure
CVSS 7.5
CVE-2019-18615 MEDIUM
CloudVision Portal <2018.2 - Info Disclosure
CVSS 4.9
CVE-2019-13947 MEDIUM
Control Center Server < V1.5.0 - Info Disclosure
CVSS 4.9
CVE-2019-19228 CRITICAL
Fronius Solar Inverter <3.14.1 - Auth Bypass
CVSS 9.8
CVE-2019-6670 MEDIUM
F5 BIG-IP 11.5.1-11.6.5 - Cleartext Storage of Sensitive Information in vCMP Hypervisor
CVSS 4.4
CVE-2019-14890 HIGH
Ansible Tower - Cleartext Storage of Sensitive Information in Database
CVSS 8.4
CVE-2019-14825 LOW
Katello 3.0.0.0-3.12.0.8 - Cleartext Storage of Sensitive Registry Credentials
CVSS 2.7
CVE-2019-5848 MEDIUM
Google Chrome < 75.0.3770.142 - Sensitive Information Exposure via Autofill Font Handling
CVSS 6.5
CVE-2019-8118 MEDIUM
Magento 2.1.0-2.1.18, 2.2.0-2.2.9, 2.3.0-2.3.2 - Cleartext Storage of Sensitive Information
CVSS 5.3
CVE-2019-4314 HIGH
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 7.5
CVE-2019-3636 HIGH
McAfee Total Protection < 16.0.R21 - Cleartext Storage of Sensitive Information in Windows Registry
CVSS 7.5
CVE-2019-10453 HIGH
Jenkins Delphix Plugin < 2.0.4 - Cleartext Storage of Sensitive Information in Global Configuration
CVSS 7.8
CVE-2019-10452 MEDIUM
Jenkins View26 Test-Reporting Plugin < 1.0.7 - Cleartext Storage of Sensitive Information in Job Config Files
CVSS 4.3
CVE-2019-10451 MEDIUM
Jenkins SOASTA CloudTest < 2.25 - Cleartext Storage of Sensitive Information in Global Configuration
CVSS 4.3
CVE-2019-10450 LOW
Jenkins ElasticBox CI Plugin < 5.0.1 - Cleartext Storage of Sensitive Information in Global Configuration
CVSS 3.3
CVE-2019-10449 HIGH
Jenkins Fortify on Demand Plugin <4.0.0 & fortify-on-demand-uploader <5.0.0 - Cleartext Storage of Sensitive Info
CVSS 8.8
CVE-2019-10447 MEDIUM
Jenkins Sofy.AI Plugin < 1.0.3 - Cleartext Storage of Sensitive Information in Job config.xml
CVSS 4.3
Details
Vulnerabilities 805