CWE-538

Insertion of Sensitive Information into Externally-Accessible File or Directory

Parent: CWE-200 - Exposure of Sensitive Information to an Unauthorized Actor

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

81 vulnerabilities with CWE-538
CVE-2022-26329 LOW
NetIQ Identity Manager <4.8.5 - Info Disclosure
CVSS 1.8
CVE-2022-23508 HIGH
Weave GitOps - Privilege Escalation
CVSS 8.8
CVE-2022-44623 MEDIUM
JetBrains TeamCity <2022.10 - Info Disclosure
CVSS 6.5
CVE-2022-20864 MEDIUM
Cisco IOS XE - Info Disclosure
CVSS 4.6
CVE-2022-0013 MEDIUM
Paloaltonetworks Cortex Xdr Agent < 5.0.12 - Information Disclosure
CVSS 5.0
CVE-2021-4471 HIGH
TG8 Firewall - Info Disclosure
CVE-2021-40363 HIGH
SIMATIC PCS 7, WinCC - Info Disclosure
CVSS 7.8
CVE-2021-3709 MEDIUM
Canonical Apport - Path Traversal
CVSS 6.5
CVE-2021-32822 MEDIUM
npm hbs - Info Disclosure
CVSS 4.0
CVE-2021-1406 MEDIUM
Cisco Unified Communications Manager - Information Disclosure
CVSS 4.9
CVE-2021-21250 HIGH
OneDev <4.0.3 - Info Disclosure
CVSS 7.7
CVE-2020-37104 HIGH
ASTPP 4.0.1 - Info Disclosure
CVSS 7.5
CVE-2019-25706 HIGH
Across DR-810 ROM-0 Unauthenticated File Disclosure
CVSS 7.5
CVE-2019-15793 MEDIUM
Linux kernel <5.3 - Privilege Escalation
CVSS 6.5
CVE-2019-6851 HIGH
Modicon - Info Disclosure
CVSS 7.5
CVE-2019-7618 MEDIUM
Elastic Code <7.3.2 - Info Disclosure
CVSS 6.5
CVE-2019-12623 MEDIUM
Cisco NFVIS - Info Disclosure
CVSS 4.3
CVE-2019-10320 MEDIUM
Jenkins Credentials Plugin <2.1.18 - Info Disclosure
CVSS 4.3
CVE-2018-20932 LOW
cPanel <70.0.23 - Info Disclosure
CVSS 2.7
CVE-2018-11798 MEDIUM
Apache Thrift Node.js <0.11.0 - Path Traversal
CVSS 6.5
CVE-2018-16970 MEDIUM
Wisetail LE <4.11.6 - IDOR
CVSS 4.3
CVE-2018-10590 HIGH
Advantech WebAccess <8.3.1 - Info Disclosure
CVSS 7.5
CVE-2018-4847 MEDIUM
SIMATIC WinCC OA Operator iOS App < V1.4 - Info Disclosure
CVSS 4.6
CVE-2017-5387 LOW
Firefox < 51 - Info Disclosure
CVSS 3.3
CVE-2017-16770 MEDIUM
Synology Surveillance Station <8.1.2-5469 - Info Disclosure
CVSS 6.5
Details
Vulnerabilities 81