← Back
CWE-312

812 CVEs • Abstraction: Base

Cleartext Storage of Sensitive Information

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

JSON object

Loading...

CVEs (812)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Arista
1Cloudvision Portal
Jun 17, 2026
Dec 19, 2019
N/A· v4
4.9 MEDIUM· v3
3.5 LOW· v2
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This onl...Show more
In CloudVision Portal (CVP) for all releases in the 2018.2 Train, under certain conditions, the application logs user passwords in plain text for certain API calls, potentially leading to user password exposure. This only affects CVP environments where: 1. Devices have enable mode passwords which are different from the user's login password, OR 2. There are configlet builders that use the Device class and specify username and password explicitly Application logs are not accessible or visible from the CVP GUI. Application logs can only be read by authorized users with privileged access to the VM hosting the CVP application.Show less
1Siemens
2Sinvr 3 Central Control Server
Sinvr 3 Video Server
Jun 17, 2026
Dec 12, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the cli...Show more
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The user configuration menu in the web interface of the Control Center Server (CCS) transfers user passwords in clear to the client (browser). An attacker with administrative privileges for the web interface could be able to read (and not only reset) passwords of other CCS users.Show less
1Fronius
66Datamanager Box 2.0 Firmware
Eco 25.0 3 S FirmwareEco 27.0 3 S Firmware+63 more
Jun 17, 2026
Dec 4, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Fronius Solar Inverter devices before 3.14.1 (HM 1.12.1) allow attackers to bypass authentication because the password for the today account is stored in the /tmp/web_users.conf file.
1F5
13Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+10 more
Jun 17, 2026
Nov 27, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.5.1-11.6.5, vCMP hypervisors are incorrectly exposing the plaintext unit key for their vCMP guests on the filesystem.
1Cloudera
1Cloudera Manager
Nov 21, 2024
Nov 26, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloudera Manager 5.x before 5.7.1 places Sensitive Data in cleartext Readable Files.
1Redhat
1Ansible Tower
Jun 17, 2026
Nov 26, 2019
N/A· v4
8.4 HIGH· v3
2.1 LOW· v2
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config'...Show more
A vulnerability was found in Ansible Tower before 3.6.1 where an attacker with low privilege could retrieve usernames and passwords credentials from the new RHSM saved in plain text into the database at '/api/v2/config' when applying the Ansible Tower license.Show less
1Theforeman
1Katello
Jun 17, 2026
Nov 25, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw...Show more
A cleartext password storage issue was discovered in Katello, versions 3.x.x.x before katello 3.12.0.9. Registry credentials used during container image discovery were inadvertently logged without being masked. This flaw could expose the registry credentials to other privileged users.Show less
1Google
1Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Incorrect font handling in autofill in Google Chrome prior to 75.0.3770.142 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
1Qtnx Project
1Qtnx
Nov 21, 2024
Nov 15, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to rem...Show more
qtnx 0.9 stores non-custom SSH keys in a world-readable configuration file. If a user has a world-readable or world-executable home directory, another local system user could obtain the private key used to connect to remote NX sessions.Show less
1Getfiregpg
1Firegpg
Nov 21, 2024
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s...Show more
FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.Show less
1Magento
1Magento
Jun 17, 2026
Nov 5, 2019
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Magento 2.1 prior to 2.1.19, Magento 2.2 prior to 2.2.10, Magento 2.3 prior to 2.3.3 uses weak cryptographic function to store the failed login attempts for customer accounts.
1Ibm
1Security Guardium Big Data Intelligence
Jun 17, 2026
Oct 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
IBM Security Guardium Big Data Intelligence (SonarG) 4.0 stores sensitive information in cleartext within a resource that might be accessible to another control sphere. IBM X-Force ID: 1610141.
1Mcafee
1Total Protection
Jun 17, 2026
Oct 28, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to...Show more
A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.Show less
1Jenkins
1Delphix
Jun 17, 2026
Oct 16, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Jenkins Delphix Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1View26 Test Reporting
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins View26 Test-Reporting Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Soasta Cloudtest
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Elasticbox Ci
Jun 17, 2026
Oct 16, 2019
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Jenkins ElasticBox CI Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Fortify On Demand
Jun 17, 2026
Oct 16, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Fortify on Demand Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Sofy.ai
Jun 17, 2026
Oct 16, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Sofy.AI Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Icescrum
Jun 17, 2026
Oct 16, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file syste...Show more
Jenkins iceScrum Plugin 1.1.4 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less