CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

90 vulnerabilities with CWE-538
CVE-2023-5937 LOW
Nozomi Networks Arc < 1.6.0 - Sensitive Information Exposure via World-Readable Configuration Files
CVSS 3.8
CVE-2023-4595 HIGH
Seattlelab SLMail - Information Exposure
CVSS 7.5
CVE-2023-46723 HIGH
lte-pic32-writer <0.0.1 - Info Disclosure
CVSS 8.9
CVE-2023-38558 MEDIUM
SIMATIC PCS neo Administration Console V4.0 and V4.0 Update 1 - Credential Leak via Windows Admin Credential Exposure
CVSS 5.5
CVE-2023-4480 MEDIUM
phpfusion < 9.10.30 - Path Traversal and Arbitrary File Write via Fusion File Manager
CVSS 5.5
CVE-2023-28444 CRITICAL
angular-server-side-configuration - Info Disclosure
CVSS 9.9
CVE-2022-43933 MEDIUM
Brocade SANnav <2.2.2 - Info Disclosure
CVSS 4.4
CVE-2022-4318 HIGH
cri-o < 1.26.0 - Arbitrary File Write via Environment Variable
CVSS 7.8
CVE-2022-26329 LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-23508 HIGH
Weave GitOps - Privilege Escalation
CVSS 8.8
CVE-2022-44623 MEDIUM
JetBrains TeamCity <2022.10 - Info Disclosure
CVSS 6.5
CVE-2022-20864 MEDIUM
Cisco IOS XE ROM Monitor - Unauthenticated Sensitive Information Exposure via Console Commands
CVSS 4.6
CVE-2022-0013 MEDIUM
Cortex XDR Agent 5.0-5.0.11, 6.1-6.1.8, 7.2-7.2.3, 7.3-7.3.1 - Arbitrary File Read via Support File
CVSS 5.0
CVE-2021-4471 HIGH
TG8 Firewall - Unauthenticated Credential Exposure via HTTP Directory Traversal
CVE-2021-40363 HIGH
SIMATIC PCS 7, WinCC - Info Disclosure
CVSS 7.8
CVE-2021-3709 MEDIUM
apport Path Traversal in check_attachment_for_errors()
CVSS 6.5
CVE-2021-32822 MEDIUM
hbs - File Disclosure via Express Render API Configuration Overwrite
CVSS 4.0
CVE-2021-1406 MEDIUM
Cisco Unified Communications Manager - Authenticated Exposure of Sensitive Information via Downloadable Files
CVSS 4.9
CVE-2021-21250 HIGH
OneDev < 4.0.3 - Arbitrary File Read via XML External Entity Injection in BuildSpec
CVSS 7.7
CVE-2020-37104 HIGH
ASTPP 4.0.1 - Unauthenticated Sensitive Information Disclosure via Database Backup Download
CVSS 7.5
CVE-2019-25717 MEDIUM
Dräger Infinity Delta/Kappa Patient Monitors Unauthenticated Log File Disclosure
CVSS 4.3
CVE-2019-25706 HIGH
Across DR-810 ROM-0 Unauthenticated File Disclosure
CVSS 7.5
CVE-2019-15793 MEDIUM
Linux kernel <5.3 - Privilege Escalation
CVSS 6.5
CVE-2019-6851 HIGH
Schneider Electric Modicon M580, M340, Premium, Quantum - File and Directory Information Exposure via TFTP Protocol
CVSS 7.5
CVE-2019-7618 MEDIUM
Elastic Code <7.3.2 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 90