Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-31581 Cleartext Storage of Sensitive Information vulnerability in Akkadianlabs OVA Appliance and Provisioning Manager
The restricted shell provided by Akkadian Provisioning Manager Engine (PME) can be escaped by abusing the 'Edit MySQL Configuration' command.
local
low complexity
akkadianlabs CWE-312
4.4
2021-07-19 CVE-2020-22741 Cleartext Storage of Sensitive Information vulnerability in Baidu Xuperchain 3.6.0
An issue was discovered in Xuperchain 3.6.0 that allows for attackers to recover any arbitrary users' private key after obtaining the partial signature in multisignature.
network
low complexity
baidu CWE-312
7.5
2021-07-15 CVE-2021-20510 Cleartext Storage of Sensitive Information vulnerability in IBM Security Verify Access 10.0.0
IBM Security Verify Access Docker 10.0.0 stores user credentials in plain clear text which can be read by a local user.
local
low complexity
ibm CWE-312
4.4
2021-07-15 CVE-2020-12731 Cleartext Storage of Sensitive Information vulnerability in Magicsmotion Flamingo 2 Firmware
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
network
low complexity
magicsmotion CWE-312
7.5
2021-07-08 CVE-2021-31816 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
network
low complexity
octopus CWE-312
7.5
2021-07-08 CVE-2021-31817 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
When configuring Octopus Server if it is configured with an external SQL database, on initial configuration the database password is written to the OctopusServer.txt log file in plaintext.
network
low complexity
octopus CWE-312
7.5
2021-07-05 CVE-2021-36158 Cleartext Storage of Sensitive Information vulnerability in Alpinelinux Aports
In the xrdp package (in branches through 3.14) for Alpine Linux, RDP sessions are vulnerable to man-in-the-middle attacks because pre-generated RSA certificates and private keys are used.
network
high complexity
alpinelinux CWE-312
5.9
2021-06-29 CVE-2021-29481 Cleartext Storage of Sensitive Information vulnerability in Ratpack Project Ratpack
Ratpack is a toolkit for creating web applications.
network
low complexity
ratpack-project CWE-312
7.5
2021-06-24 CVE-2021-29950 Cleartext Storage of Sensitive Information vulnerability in Mozilla Thunderbird
Thunderbird unprotects a secret OpenPGP key prior to using it for a decryption, signing or key import task.
network
low complexity
mozilla CWE-312
7.5
2021-06-24 CVE-2021-29954 Cleartext Storage of Sensitive Information vulnerability in Mozilla Hubs Cloud Reticulum
Proxy functionality built into Hubs Cloud’s Reticulum software allowed access to internal URLs, including the metadata service.
network
low complexity
mozilla CWE-312
critical
9.8