CWE-524
68 CVEs • Abstraction: Base
Use of Cache Containing Sensitive Information
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
CVEs (68)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in MediaWiki before 1.35.5, 1.36.x before 1.36.3, and 1.37.x before 1.37.1. The REST API publicly caches results from private wikis. |
The issue was addressed with improved handling of caches. This issue is fixed in iOS 16. An app may be able to access user-sensitive data. |
Use of Cache Containing Sensitive Information in GitHub repository ikus060/rdiffweb prior to 2.4.8. |
1Whatsapp 2Whatsapp Whatsapp BusinessJun 17, 2026 Apr 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A cache configuration issue prior to WhatsApp for Android v2.21.4.18 and WhatsApp Business for Android v2.21.4.18 may have allowed a third party with access to the device’s external storage to read cached TLS material. |
The AccessLogFilter class in Jira before version 8.4.0 allows remote anonymous attackers to learn details about other users, including their username, via an information expose through caching vulnerability when Jira is...Show more |
3Kubernetes NetappRedhat3Kubernetes Openshift Container PlatformTridentJun 17, 2026 Apr 22, 2019 N/A· v4 5.0 MEDIUM· v3 1.9 LOW· v2 In Kubernetes v1.8.x-v1.14.x, schema info is cached by kubectl in the location specified by --cache-dir (defaulting to $HOME/.kube/http-cache), written with world-writeable permissions (rw-rw-rw-). If --cache-dir is spec...Show more |
6Debian FedoraprojectFreebsd+3 more9Backports Sle Debian LinuxFedora+6 moreJun 17, 2026 Apr 17, 2019 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. Th...Show more |
5Fedoraproject FreebsdOpensuse+2 more8Backports Sle FedoraFreebsd+5 moreJun 17, 2026 Apr 17, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing differences and cache access patterns. An attacker may be able to gain leaked information f...Show more |