CWE-212— Improper Removal of Sensitive Information Before Storage or Transfer
77 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-212page 1 of 2
- CVE-2017-15113HIGHCVSS 7.22018-07-27
ovirt-engine before version 4.1.7.6 with log level set to DEBUG includes passwords in the log file without masking. Only administrators can change the log level and only administrators can access the logs. This presents a risk when debug-l…
- CVE-2018-1062MEDIUMCVSS 5.32018-03-06
A vulnerability was discovered in oVirt 4.1.x before 4.1.9, where the combination of Enable Discard and Wipe After Delete flags for VM disks managed by oVirt, could cause a disk to be incompletely zeroed when removed from a VM. If the same…
- CVE-2018-5559LOWCVSS 3.42018-11-28
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent…
- CVE-2018-6337HIGHCVSS 7.5EG 7.52018-12-31
folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly lib…
- CVE-2019-11243HIGHCVSS 8.12019-04-22
In Kubernetes v1.12.0-v1.12.4 and v1.13.0, the rest.AnonymousClientConfig() method returns a copy of the provided config, with credentials removed (bearer token, username/password, and client certificate/key data). In the affected versions…
- CVE-2019-13402HIGHCVSS 8.82019-07-08
/usr/sbin/default.sh and /usr/apache/htdocs/cgi-bin/admin/hardfactorydefault.cgi on Dynacolor FCM-MB40 v1.2.0.0 devices implement an incomplete factory-reset process. A backdoor can persist because neither system accounts nor the set of se…
- CVE-2019-19362MEDIUMCVSS 6.5EG 6.52019-12-02
An issue was discovered in the Chat functionality of the TeamViewer desktop application 14.3.4730 on Windows. (The vendor states that it was later fixed.) Upon login, every communication is saved within Windows main memory. When a user log…
- CVE-2019-20637HIGHCVSS 7.5EG 7.52020-04-08
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear a pointer between the handling of one client request and the next request within the same connection. This s…
- CVE-2020-11198MEDIUMCVSS 6.7EG 6.72021-02-22
Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon…
- CVE-2020-11684CRITICALCVSS 9.1EG 9.12020-09-14
AT91bootstrap before 3.9.2 does not properly wipe encryption and authentication keys from memory before passing control to a less privileged software component. This can be exploited to disclose these keys and subsequently encrypt and sign…
- CVE-2020-11740MEDIUMCVSS 5.5EG 5.52020-04-14
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling ha…
- CVE-2020-13179MEDIUMCVSS 5.5EG 5.52020-08-11
Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via …
- CVE-2020-14301MEDIUMCVSS 6.5EG 6.52021-05-27
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensi…
- CVE-2020-14370MEDIUMCVSS 5.3EG 5.32020-09-23
An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environme…
- CVE-2020-15024MEDIUMCVSS 5.5EG 5.52020-09-10
An issue was discovered in the Login Password feature of the Password Manager component in Avast Antivirus 20.1.5069.562. An entered password continues to be stored in Windows main memory after a logout, and after a Lock Vault operation.
- CVE-2020-15094HIGHCVSS 8.0EG 8.02020-09-02
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control th…
- CVE-2020-1940HIGHCVSS 7.5EG 7.52020-01-28
The optional initial password change and password expiration features present in Apache Jackrabbit Oak 1.2.0 to 1.22.0 are prone to a sensitive information disclosure vulnerability. The code mandates the changed password to be passed as an…
- CVE-2020-25635MEDIUMCVSS 5.0EG 5.02020-10-05
A flaw was found in Ansible Base when using the aws_ssm connection plugin as garbage collector is not happening after playbook run is completed. Files would remain in the bucket exposing the data. This issue affects directly data confident…
- CVE-2020-26965MEDIUMCVSS 6.5EG 6.52020-12-09
Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their passwor…
- CVE-2020-36476HIGHCVSS 7.5EG 7.52021-08-23
An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory.
- CVE-2020-3874MEDIUMCVSS 5.3EG 5.32020-02-27
An issued existed in the naming of screenshots. The issue was corrected with improved naming. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1. Screenshots of the Messages app may reveal additional message content.
- CVE-2020-8696MEDIUMCVSS 5.5EG 5.52020-11-12
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
- CVE-2020-9780LOWCVSS 3.3EG 3.32020-04-01
The issue was resolved by clearing application previews when content is deleted. This issue is fixed in iOS 13.4 and iPadOS 13.4. A local user may be able to view deleted content in the app switcher.
- CVE-2021-0340HIGHCVSS 8.8EG 8.82021-02-10
In parseNextBox of IsoInterface.java, there is a possible leak of unredacted location information due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User inter…
- CVE-2021-26341MEDIUMCVSS 6.5EG 6.52022-03-11
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
- CVE-2021-28689MEDIUMCVSS 5.5EG 5.52021-06-11
x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen was able to use it t…
- CVE-2021-3031MEDIUMCVSS 4.3EG 4.32021-01-13
Padding bytes in Ethernet packets on PA-200, PA-220, PA-500, PA-800, PA-2000 Series, PA-3000 Series, PA-3200 Series, PA-5200 Series, and PA-7000 Series firewalls are not cleared before the data frame is created. This leaks a small amount o…
- CVE-2021-31780HIGHCVSS 7.5EG 7.52021-04-23
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing group object is ignore…
- CVE-2021-32658MEDIUMCVSS 4.7EG 4.72021-06-08
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such…
- CVE-2021-33080MEDIUMCVSS 6.8EG 6.82022-05-12
Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to potentially enable infor…
- CVE-2021-33082MEDIUMCVSS 4.6EG 4.62022-05-12
Sensitive information in resource not removed before reuse in firmware for some Intel(R) SSD and Intel(R) Optane(TM) SSD Products may allow an unauthenticated user to potentially enable information disclosure via physical access.
- CVE-2021-3602MEDIUMCVSS 5.5EG 5.52022-03-03
An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and grandparent process…
- CVE-2021-38554MEDIUMCVSS 5.3EG 5.32021-08-13
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases.
- CVE-2021-39891MEDIUMCVSS 5.9EG 4.92021-10-05
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.
- CVE-2021-46813HIGHCVSS 7.5EG 7.52022-06-13
Vulnerability of residual files not being deleted after an update in the ChinaDRM module. Successful exploitation of this vulnerability may affect availability.
- CVE-2022-0171MEDIUMCVSS 5.5EG 5.52022-08-26
A flaw was found in the Linux kernel. The existing KVM SEV API has a vulnerability that allows a non-root (host) user-level application to crash the host kernel by creating a confidential guest VM instance in AMD CPU that supports Secure E…
- CVE-2022-0355HIGHCVSS 8.8EG 8.82022-01-26
Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1.
- CVE-2022-0536LOWCVSS 2.6EG 2.62022-02-09
Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8.
- CVE-2022-1650HIGHCVSS 8.1EG 8.12022-05-12
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.
- CVE-2022-1893MEDIUMCVSS 4.6EG 5.32022-05-31
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository polonel/trudesk prior to 1.2.3.
- CVE-2022-22779LOWCVSS 3.7EG 3.72022-02-09
The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a sleep state before …
- CVE-2022-23605MEDIUMCVSS 4.4EG 4.42022-02-04
Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. In versions before 2022-01-27-production…
- CVE-2022-23633HIGHCVSS 7.4EG 7.42022-02-11
Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` will not know to res…
- CVE-2022-24719LOWCVSS 2.6EG 2.62022-03-01
Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a request that inclu…
- CVE-2022-24798HIGHCVSS 7.5EG 7.52022-03-31
Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exports. This may have…
- CVE-2022-25187MEDIUMCVSS 6.5EG 6.52022-02-15
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.
- CVE-2022-2818CRITICALCVSS 9.8EG 9.82022-08-15
Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository cockpit-hq/cockpit prior to 2.2.2.
- CVE-2022-29900MEDIUMCVSS 6.5EG 6.52022-07-12
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
- CVE-2022-30617HIGHCVSS 8.8EG 8.82022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for other admin panel users that have a relationship (e.g., created by, updated by) with content acce…
- CVE-2022-30618HIGHCVSS 7.5EG 7.52022-05-19
An authenticated user with access to the Strapi admin panel can view private and sensitive data, such as email and password reset tokens, for API users if content types accessible to the authenticated user contain relationships to API user…
Map vulnerabilities like CWE-212 to your infrastructure
EchelonGraph correlates every CVE — across CWE-212 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →