Threats Tagged 'cwe-214'
View all threats tagged with 'cwe-214'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-214'
Click on any threat for detailed analysis and mitigation recommendations
0 In wsl-pro-service before 0.1.19ubuntu3, the service component which runs as root inside each WSL instance attaches the instance to Ubuntu Pro by executing the pro client with the Ubuntu Pro token passed as a command-line argument (pro attach <token>). On systems where /proc is mounted without process-hiding mitigations (such as hidepid), which is the default in WSL, an unprivileged local user or process in the same WSL instance can read the token from /proc/<pid>/cmdline while the attach process is running. The leaked token could then be used to attach other machines to the victim's Ubuntu Pro subscription and gain unauthorized access to Ubuntu Pro services. Join the discussion | CVE Database V5 | 09/29/2026, 14:11:19 UTC Added: 09/29/2026, 14:33:27 UTC |
0 microsandbox is an easy, fast, local-first microVM runtime and library. Prior to 0.5.10, sdk/rust/lib/runtime/spawn.rs serializes NetworkConfig secret values into the --network-config argument and passes per-sandbox secrets through repeated --env arguments accepted by crates/cli/lib/sandbox_cmd.rs. Other local users or co-resident processes can read these values through the host process table, including /proc process command lines on Linux and process listings on Linux and macOS, for the lifetime of the sandbox. Exploitation does not require code execution inside the sandbox or access to the spawning user's session, and can disclose host-side API keys, tokens, and environment secrets on shared hosts, CI runners, and developer systems. This issue is fixed in version 0.5.10. Join the discussion | CVE Database V5 | 09/18/2026, 20:41:31 UTC Added: 09/18/2026, 22:13:01 UTC |
0 A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM) credentials, including plaintext passwords, by inspecting process command-line arguments during VM creation or installation. The cockpit-machines component passes password values directly on the command line, making them visible to other local users on systems where process arguments are not restricted. Successful exploitation leads to information disclosure, potentially compromising VM access. Join the discussion | CVE Database V5 | 09/18/2026, 17:53:54 UTC Added: 09/18/2026, 18:02:20 UTC |
0 A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running processes to expose sensitive guest virtual machine (VM) credentials, such as `rootPassword` and `userPassword`. This occurs when the `install_machine.py` script passes these credentials as a JSON command-line argument during VM creation or installation. The exposure is limited to the period when the installation workflow is active and depends on host process-visibility policies. Join the discussion | CVE Database V5 | 09/18/2026, 17:53:35 UTC Added: 09/18/2026, 18:02:20 UTC |
0 A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process metadata to disclose a sensitive Red Hat Subscription Management (RHSM) offline token. The token is exposed when it is passed as a command-line argument to a helper script during the token validation process. Successful exploitation could lead to the compromise of confidentiality, as the exposed token can be used to request access tokens. Join the discussion | CVE Database V5 | 09/18/2026, 17:53:29 UTC Added: 09/18/2026, 18:02:20 UTC |
0 CVE-2026-80158 is a vulnerability in the ipa_getkeytab module of the community.general Ansible collection used by Red Hat Ceph Storage 5. The module's bind_pw parameter is not marked with no_log, causing the LDAP bind password to be exposed in cleartext in system logs, module outputs, and process listings. This exposure allows local users or attackers with access to logs or job outputs to obtain sensitive directory bind credentials. The vulnerability has a medium severity rating with a CVSS score of 5.5. Join the discussion | GCVE Database | 08/26/2026, 22:06:07 UTC Added: 08/27/2026, 15:13:13 UTC |
0 NVIDIA NemoClaw has a vulnerability (CVE-2026-65088) involving the invocation of a process using visible sensitive information. Exploiting this flaw could lead to unauthorized disclosure of sensitive information. The vulnerability has a medium severity rating with a CVSS score of 5.5. No affected versions or patch information are provided, and there are no known exploits in the wild. Join the discussion | CVE Database V5 | 08/25/2026, 20:15:32 UTC Added: 08/25/2026, 20:23:13 UTC |
0 CVE-2026-76054 is a vulnerability in Black Duck blackduck-c-cpp versions 1.0.17 through 3.0.6 that allows an actor with code execution capability within the scanned project's build to access the Black Duck API token. This occurs because the token, when supplied via the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variables, is exposed through the ambient process environment inherited by subprocesses during build capture and signature scanning. Upgrading to version 3.0.7 or later addresses the vulnerability, but prior token exposure requires token rotation. Join the discussion | CVE Database V5 | 08/24/2026, 14:16:36 UTC Added: 08/24/2026, 14:22:41 UTC |
CVE-2026-18915 is a vulnerability in the eta-otp-lock software by TÜBİTAK BİLGEM Software Technologies Research Institute that involves invocation of a process using visible sensitive information. This flaw allows system footprinting and affects versions prior to 1.0.4. The vulnerability has a medium severity rating with a CVSS score of 5. There is no official patch or remediation level currently provided by the vendor. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:16 UTC Added: 08/06/2026, 08:11:48 UTC |
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL component passed via the command-line arguments (argv), resulting in a URL format such as https://bearer:<token>@esm.ubuntu.com/.../. On systems utilizing a default-mounted /proc file system where process-hiding mitigations (such as hidepid) are disabled, an unprivileged local attacker can monitor system processes and read the sensitive bearer token directly from /proc/cmdline while the helper process is actively running. This leaked token can subsequently be used to gain unauthorized access to the victim's Ubuntu Pro or Expanded Security Maintenance (ESM) repositories. Join the discussion | CVE Database V5 | 07/16/2026, 12:12:27 UTC Added: 07/16/2026, 12:48:28 UTC |
Showing 1 to 10 of 18 results