CWE-212
124 CVEs • Abstraction: Base
Improper Removal of Sensitive Information Before Storage or Transfer
The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.
CVEs (124)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Intel 7Optane Memory H10 With Solid State Storage Firmware Optane Memory H20 With Solid State Storage FirmwareOptane Ssd 900p Firmware+4 moreJun 17, 2026 May 12, 2022 N/A· v4 6.8 MEDIUM· v3 4.6 MEDIUM· v2 Exposure of sensitive system information due to uncleared debug information in firmware for some Intel(R) SSD DC, Intel(R) Optane(TM) SSD and Intel(R) Optane(TM) SSD DC Products may allow an unauthenticated user to poten...Show more |
2Debian Eventsource2Debian Linux EventsourceJun 17, 2026 May 12, 2022 N/A· v4 9.3 CRITICAL· v3 5.8 MEDIUM· v2 Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2. |
1Internet Routing Registry Daemon Project 1Internet Routing Registry Daemon Jun 17, 2026 Mar 31, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. IRRd did not always filter password hashes in query responses relating to `mntner` objects and database exp...Show more |
1Amd 126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Mar 11, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage. |
2Buildah Project Redhat4Buildah Enterprise LinuxEnterprise Linux For Ibm Z Systems+1 moreJun 17, 2026 Mar 3, 2022 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An information disclosure flaw was found in Buildah, when building containers using chroot isolation. Running processes in container builds (e.g. Dockerfile RUN commands) can access environment variables from parent and...Show more |
1Fluture Node Project 1Fluture Node Jun 17, 2026 Mar 1, 2022 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Fluture-Node is a FP-style HTTP and streaming utils for Node based on Fluture. Using `followRedirects` or `followRedirectsWith` with any of the redirection strategies built into fluture-node 4.0.0 or 4.0.1, paired with a...Show more |
Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Feb 11, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Action Pack is a framework for handling and responding to web requests. Under certain circumstances response bodies will not be closed. In the event a response is *not* notified of a `close`, `ActionDispatch::Executor` w...Show more |
The Keybase Clients for macOS and Windows before version 5.9.0 fails to properly remove exploded messages initiated by a user. This can occur if the receiving user switches to a non-chat feature and places the host in a...Show more |
1Follow Redirects Project 1Follow Redirects Jun 17, 2026 Feb 9, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Improper Removal of Sensitive Information Before Storage or Transfer in NPM follow-redirects prior to 1.14.8. |
Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. In versions before 20...Show more |
1Simple Get Project 1Simple Get Jun 17, 2026 Jan 26, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Removal of Sensitive Information Before Storage or Transfer in NPM simple-get prior to 4.0.1. |
In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure. |
2Arm Debian2Debian Linux Mbed TlsJun 17, 2026 Aug 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Mbed TLS before 2.24.0 (and before 2.16.8 LTS and before 2.7.17 LTS). There is missing zeroization of plaintext buffers in mbedtls_ssl_read to erase unused application data from memory. |
HashiCorp Vault and Vault Enterprise’s UI erroneously cached and exposed user-viewed secrets between sessions in a single shared browser. Fixed in 1.8.0 and pending 1.7.4 / 1.6.6 releases. |
x86: Speculative vulnerabilities with bare (non-shim) 32-bit PV guests 32-bit x86 PV guest kernels run in ring 1. At the time when Xen was developed, this area of the i386 architecture was rarely used, which is why Xen w...Show more |
Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitiv...Show more |
2Netapp Redhat13Codeready Linux Builder Enterprise LinuxEnterprise Linux Eus+10 moreJun 17, 2026 May 27, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to acces...Show more |
In app/Model/MispObject.php in MISP 2.4.141, an incorrect sharing group association could lead to information disclosure on an event edit. When an object has a sharing group associated with an event edit, the sharing gro...Show more |
1Qualcomm 301Aqt1000 Firmware Ar8031 FirmwareAr8035 Firmware+298 moreJun 17, 2026 Feb 22, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consu...Show more |