CWE-312— Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.— MITRE CWE catalog
903 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-312page 13 of 19
- CVE-2023-24439MEDIUMCVSS 5.5EG 5.52023-01-26
Jenkins JIRA Pipeline Steps Plugin 2.0.165.v8846cf59f3db and earlier stores the private keys unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file …
- CVE-2023-24055MEDIUMCVSS 5.5EG 5.52023-01-22
KeePass through 2.53 (in a default installation) allows an attacker, who has write access to the XML configuration file, to obtain the cleartext passwords by adding an export trigger. NOTE: the vendor's position is that the password databa…
- CVE-2022-45787MEDIUMCVSS 5.5EG 5.52023-01-06
Unproper laxist permissions on the temporary files used by MIME4J TempFileStorageProvider may lead to information disclosure to other local users. This issue affects Apache James MIME4J version 0.8.8 and prior versions. We recommend users…
- CVE-2022-47512MEDIUMCVSS 5.5EG 5.52022-12-19
Sensitive information was stored in plain text in a file that is accessible by a user with a local account in Hybrid Cloud Observability (HCO)/ SolarWinds Platform 2022.4. No other versions are affected
- CVE-2022-31697MEDIUMCVSS 5.5EG 5.52022-12-13
The vCenter Server contains an information disclosure vulnerability due to the logging of credentials in plaintext. A malicious actor with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migra…
- CVE-2022-4312MEDIUMCVSS 5.5EG 5.52022-12-12
A cleartext storage of sensitive information vulnerability exists in PcVue versions 8.10 through 15.2.3. This could allow an unauthorized user with access the email and short messaging service (SMS) accounts configuration files to discove…
- CVE-2022-33918MEDIUMCVSS 5.5EG 5.52022-10-12
Dell GeoDrive, Versions 2.1 - 2.2, contains an information disclosure vulnerability. An authenticated non-admin user could potentially exploit this vulnerability and gain access to sensitive information.
- CVE-2015-1931MEDIUMCVSS 5.5EG 5.52022-09-29
IBM Java Security Components in IBM SDK, Java Technology Edition 8 before SR1 FP10, 7 R1 before SR3 FP10, 7 before SR9 FP10, 6 R1 before SR8 FP7, 6 before SR16 FP7, and 5.0 before SR16 FP13 stores plaintext information in memory dumps, whi…
- CVE-2021-39009MEDIUMCVSS 5.5EG 5.52022-09-01
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 stores user credentials in plain clear text which can be read by a local privileged user. IBM X-Force ID: 213554.
- CVE-2021-3585MEDIUMCVSS 5.5EG 5.52022-08-26
A flaw was found in openstack-tripleo-heat-templates. Plain passwords from RHSM exist in the logs during OSP13 deployment with subscription-manager.
- CVE-2022-2569MEDIUMCVSS 5.5EG 5.52022-08-24
The affected device stores sensitive information in cleartext, which may allow an authenticated user to access session data stored in the OAuth database belonging to legitimate users
- CVE-2022-20219MEDIUMCVSS 5.5EG 5.52022-07-13
In multiple functions of StorageManagerService.java and UserManagerService.java, there is a possible way to leave user's directories unencrypted due to a logic error in the code. This could lead to local information disclosure with no addi…
- CVE-2022-22367MEDIUMCVSS 5.5EG 5.52022-07-01
IBM UrbanCode Deploy (UCD) 6.2.7.15, 7.0.5.10, 7.1.2.6, and 7.2.2.1 could disclose sensitive database information to a local user in plain text. IBM X-Force ID: 221008.
- CVE-2022-22478MEDIUMCVSS 5.5EG 5.52022-06-30
IBM Spectrum Protect Client 8.1.0.0 through 8.1.14.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 225886.
- CVE-2021-41639MEDIUMCVSS 5.5EG 5.52022-06-24
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
- CVE-2022-22484MEDIUMCVSS 5.5EG 5.52022-05-17
IBM Spectrum Protect Operations Center 8.1.12 and 8.1.13 could allow a local attacker to obtain sensitive information, caused by plain text user account passwords potentially being stored in the browser's application command history. By ac…
- CVE-2022-29868MEDIUMCVSS 5.5EG 5.52022-05-09
1Password for Mac 7.2.4 through 7.9.x before 7.9.3 is vulnerable to a process validation bypass. Malicious software running on the same computer can exfiltrate secrets from 1Password provided that 1Password is running and is unlocked. Affe…
- CVE-2022-23234MEDIUMCVSS 5.5EG 5.52022-03-16
SnapCenter versions prior to 4.5 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext HANA credentials.
- CVE-2020-14480MEDIUMCVSS 5.5EG 5.52022-02-24
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
- CVE-2022-23129MEDIUMCVSS 5.5EG 5.52022-01-21
Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS GENESIS64 versions 10.90 to 10.97 allows a local authenticated attacker to gain authentication information …
- CVE-2021-31821MEDIUMCVSS 5.5EG 5.52022-01-19
When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image
- CVE-2021-20171MEDIUMCVSS 5.5EG 5.52021-12-30
Netgear RAX43 version 1.0.3.96 stores sensitive information in plaintext. All usernames and passwords for the device's associated services are stored in plaintext on the device. For example, the admin password is stored in plaintext in the…
- CVE-2021-38949MEDIUMCVSS 5.5EG 5.52021-11-16
IBM MQ 7.5, 8.0, 9.0 LTS, 9.1 CD, and 9.1 LTS stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 211403.
- CVE-2020-10053MEDIUMCVSS 5.5EG 5.52021-11-09
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V2.12). The affected application writes sensitive data, such as database credentials in configuration files. A local attacker with access to the configura…
- CVE-2021-41023MEDIUMCVSS 5.5EG 5.52021-11-02
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files
- CVE-2021-40454MEDIUMCVSS 5.5EG 5.52021-10-13
Rich Text Edit Control Information Disclosure Vulnerability
- CVE-2021-29904MEDIUMCVSS 5.5EG 5.52021-09-23
IBM Jazz for Service Management 1.1.3.10 and IBM Tivoli Netcool/OMNIbus_GUI displays user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 207610.
- CVE-2021-37452MEDIUMCVSS 5.5EG 5.52021-07-25
NCH Quorum v2.03 and earlier allows local users to discover cleartext login information relating to users by reading the local .dat configuration files.
- CVE-2021-27487MEDIUMCVSS 5.5EG 5.52021-06-16
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
- CVE-2021-28858MEDIUMCVSS 5.5EG 5.52021-06-15
TP-Link's TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information.
- CVE-2018-16498MEDIUMCVSS 5.5EG 5.52021-05-26
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as SNMP, and SSL and Trust keystores.
- CVE-2021-31539MEDIUMCVSS 5.5EG 5.52021-04-23
Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local user is able to read usernames and passwords.
- CVE-2020-11924MEDIUMCVSS 5.5EG 5.52021-04-02
An issue was discovered in WiZ Colors A60 1.14.0. Wi-Fi credentials are stored in cleartext in flash memory, which presents an information-disclosure risk for a discarded or resold device.
- CVE-2020-11923MEDIUMCVSS 5.5EG 5.52021-04-02
An issue was discovered in WiZ Colors A60 1.14.0. API credentials are locally logged.
- CVE-2021-26579MEDIUMCVSS 5.5EG 5.52021-03-30
A security vulnerability in HPE Unified Data Management (UDM) could allow the local disclosure of privileged information (CWE-321: Use of Hard-coded Cryptographic Key in a product). HPE has provided updates to versions 1.2009.0 and 1.2101.…
- CVE-2020-4944MEDIUMCVSS 5.5EG 5.52021-03-30
IBM UrbanCode Deploy (UCD) 7.0.3.0, 7.0.4.0, 7.0.5.3, 7.0.5.4, 7.1.0.0, 7.1.1.0, 7.1.1.1, and 7.1.1.2, stores keystore passwords in plain text after a manual edit, which can be read by a local user. IBM X-Force ID: 191944.
- CVE-2020-4884MEDIUMCVSS 5.5EG 5.52021-03-30
IBM UrbanCode Deploy (UCD) 6.2.7.9, 7.0.5.4, and 7.1.1.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 190908.
- CVE-2021-23827MEDIUMCVSS 5.5EG 5.52021-02-23
Keybase Desktop Client before 5.6.0 on Windows and macOS, and before 5.6.1 on Linux, allows an attacker to obtain potentially sensitive media (such as private pictures) in the Cache and uploadtemps directories. It fails to effectively clea…
- CVE-2021-20408MEDIUMCVSS 5.5EG 5.52021-02-12
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could disclose highly sensitive information to a local user due to inproper storage of a plaintext cryptographic key. IBM X-Force ID: 198187.
- CVE-2021-27205MEDIUMCVSS 5.5EG 5.52021-02-12
Telegram before 7.4 (212543) Stable on macOS stores the local copy of self-destructed messages in a sandbox path, leading to sensitive information disclosure.
- CVE-2021-27204MEDIUMCVSS 5.5EG 5.52021-02-12
Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
- CVE-2021-26550MEDIUMCVSS 5.5EG 5.52021-02-09
An issue was discovered in SmartFoxServer 2.17.0. Cleartext password disclosure can occur via /config/server.xml.
- CVE-2020-13473MEDIUMCVSS 5.5EG 5.52020-12-28
NCH Express Accounts 8.24 and earlier allows local users to discover the cleartext password by reading the configuration file.
- CVE-2020-25677MEDIUMCVSS 5.5EG 5.52020-12-08
A flaw was found in Ceph-ansible v4.0.41 where it creates an /etc/ceph/iscsi-gateway.conf with insecure default permissions. This flaw allows any user on the system to read sensitive information within this file. The highest threat from th…
- CVE-2020-27557MEDIUMCVSS 5.5EG 5.52020-11-17
Unprotected Storage of Credentials vulnerability in BASETech GE-131 BT-1837836 firmware 20180921 allows local users to gain access to the video streaming username and password via SQLite files containing plain text credentials.
- CVE-2020-8276MEDIUMCVSS 5.5EG 5.52020-11-09
The implementation of Brave Desktop's privacy-preserving analytics system (P3A) between 1.1 and 1.18.35 logged the timestamp of when the user last opened an incognito window, including Tor windows. The intended behavior was to log the time…
- CVE-2020-2274MEDIUMCVSS 5.5EG 5.52020-09-16
Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
- CVE-2020-15485MEDIUMCVSS 5.5EG 5.52020-08-26
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.
- CVE-2020-7517MEDIUMCVSS 5.5EG 5.52020-07-23
A CWE-312: Cleartext Storage of Sensitive Information vulnerability exists in Easergy Builder (Version 1.4.7.2 and older) which could allow an attacker to read user credentials.
- CVE-2020-4369MEDIUMCVSS 5.5EG 5.52020-07-22
IBM Verify Gateway (IVG) 1.0.0 and 1.0.1 stores highly sensitive information in cleartext that could be obtained by a user. IBM X-Force ID: 179004.
Map vulnerabilities like CWE-312 to your infrastructure
EchelonGraph correlates every CVE — across CWE-312 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →