← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Elspec Ltd
1G5dfr Firmware
Jun 17, 2026
Mar 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Elspec G5 digital fault recorder versions 1.1.4.15 and before. Cleartext passwords and hashes are exposed through log files.
-
-
Jun 17, 2026
Mar 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in Newland Nquire 1000 Interactive Kiosk version NQ1000-II_G_V1.00.011, allows remote attackers to obtain sensitive information via cleartext credential storage in backup.htm component.
1Jfinalcms Project
1Jfinalcms
Jun 17, 2026
Mar 7, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SQL injection vulnerability in Jfinalcms v.5.0.0 allows a remote attacker to obtain sensitive information via /admin/admin name parameter.
1Cisco
1Duo Authentication For Windows Logon And Rdp
Jun 17, 2026
Mar 6, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vuln...Show more
A vulnerability in the logging component of Cisco Duo Authentication for Windows Logon and RDP could allow an authenticated, local attacker to view sensitive information in clear text on an affected system. This vulnerability is due to improper storage of an unencrypted registry key in certain logs. An attacker could exploit this vulnerability by accessing the logs on an affected system. A successful exploit could allow the attacker to view sensitive information in clear text.Show less
1Ibm
1Storage Defender Resiliency Service
Jun 17, 2026
Feb 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783.
1Tendacn
1Cp3 Firmware
Jun 17, 2026
Feb 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.
1Ibm
1Security Access Manager Container
Jun 17, 2026
Feb 7, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
IBM Security Access Manager Container 10.0.0.0 through 10.0.6.1 temporarily stores sensitive information in files that could be accessed by a local user. IBM X-Force ID: 254657.
1Silabs
1Gecko Software Development Kit
Jun 17, 2026
Feb 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Prior to v7.4.0, Ember ZNet is vulnerable to a denial of service attack through manipulation of the NWK sequence number
1Apache
3Airflow
Airflow Cncf KubernetesApache Airflow Providers Cncf Kubernetes
Jul 2, 2026
Jan 24, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by...Show more
Since version 5.2.0, when using deferrable mode with the path of a Kubernetes configuration file for authentication, the Airflow worker serializes this configuration file as a dictionary and sends it to the triggerer by storing it in metadata without any encryption. Additionally, if used with an Airflow version between 2.3.0 and 2.6.0, the configuration dictionary will be logged as plain text in the triggerer service without masking. This allows anyone with access to the metadata or triggerer log to obtain the configuration file and use it to access the Kubernetes cluster. This behavior was changed in version 7.0.0, which stopped serializing the file contents and started providing the file path instead to read the contents into the trigger. Users are recommended to upgrade to version 7.0.0, which fixes this issue.Show less
1Tp Link
1Tapo
Jul 9, 2026
Jan 9, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
1Bestwebsoft
1Like & Share
Jun 17, 2026
Dec 26, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The BestWebSoft's Like & Share WordPress plugin before 2.74 discloses the content of password protected posts to unauthenticated users via a meta tag
1Weseek
1Growi
Jun 17, 2026
Dec 26, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access t...Show more
The App Settings (/admin/app) page in GROWI versions prior to v6.0.6 stores sensitive information in cleartext form. As a result, the Secret access key for external service may be obtained by an attacker who can access the App Settings page.Show less
2Infinispan
Redhat
3Data Grid
InfinispanJboss Data Grid
Jun 17, 2026
Dec 18, 2023
N/A· v4
2.7 LOW· v3
N/A· v2
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text a...Show more
A flaw was found in Infinispan. When serializing the configuration for a cache to XML/JSON/YAML, which contains credentials (JDBC store with connection pooling, remote store), the credentials are returned in clear text as part of the configuration.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Dec 15, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view...Show more
XWiki Platform is a generic wiki platform. Starting in 7.2-milestone-2 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, the Solr-based search in XWiki discloses the password hashes of all users to anyone with view right on the respective user profiles. By default, all user profiles are public. This vulnerability also affects any configurations used by extensions that contain passwords like API keys that are viewable for the attacker. Normally, such passwords aren't accessible but this vulnerability would disclose them as plain text. This has been patched in XWiki 14.10.15, 15.5.2 and 15.7RC1. There are no known workarounds for this vulnerability. Show less
1Jenkins
1Paaslane Estimate
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier does not mask PaaSLane authentication tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
1Jenkins
1Paaslane Estimate
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission...Show more
Jenkins PaaSLane Estimate Plugin 1.0.4 and earlier stores PaaSLane authentication tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Show less
1Jenkins
1Dingding Json Pusher
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier does not mask access tokens displayed on the job configuration form, increasing the potential for attackers to observe and capture them.
1Jenkins
1Dingding Json Pusher
Jun 17, 2026
Dec 13, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the...Show more
Jenkins Dingding JSON Pusher Plugin 2.0 and earlier stores access tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system.Show less
1Heartcombo
1Devise
May 27, 2025
Dec 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
The Devise gem before 3.5.4 for Ruby mishandles Remember Me cookies for sessions, which may allow an adversary to obtain unauthorized persistent application access.
1Siemens
1Simatic Step 7
Jun 17, 2026
Dec 12, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-...Show more
A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) (All versions < V19). An information disclosure vulnerability could allow a local attacker to gain access to the access level password of the SIMATIC S7-1200 and S7-1500 CPUs, when entered by a legitimate user in the hardware configuration of the affected application.Show less