Threats Tagged 'cwe-312'
View all threats tagged with 'cwe-312'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-312'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-50267: CWE-312: Cleartext Storage of Sensitive Information in SteeltoeOSS Steeltoe.Configuration.AbstractionsCVE-2026-50267 0 Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Configuration.Abstractions 4.0.0 through 4.1.0, when MySQL or PostgreSQL service bindings from `VCAP_SERVICES` include TLS client credentials, the Connectors library writes those credentials to temporary files in `Path.GetTempPath()` using `File.CreateText`. On Linux, `File.CreateText` creates files with mode `0644` (world-readable) under the process umask, and the files are never deleted. The same key material is protected at mode `0400` in `/proc/<pid>/environ`. Steeltoe.Configuration.Abstractions version 4.2.0 patches the issue. If an immediate upgrade is not possible, prevent other processes from running in the container under a different UID with access to `/tmp`. Join the discussion | CVE Database V5 | 06/17/2026, 21:57:09 UTC Added: 06/17/2026, 22:35:08 UTC |
CVE-2026-10786: CWE-312 Cleartext storage of sensitive information in Devolutions ServerCVE-2026-10786 0 Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier Join the discussion | CVE Database V5 | 06/08/2026, 18:26:09 UTC Added: 06/08/2026, 19:03:40 UTC |
CVE-2024-6921: CWE-312 Cleartext Storage of Sensitive Information in NAC Telecommunication Systems Inc. NACPremiumCVE-2024-6921 0 Cleartext Storage of Sensitive Information vulnerability in NAC Telecommunication Systems Inc. NACPremium allows Retrieve Embedded Sensitive Data. This issue affects NACPremium: through 01082024. Join the discussion | CVE Database V5 | 09/02/2024, 13:24:14 UTC Added: 06/03/2026, 19:52:07 UTC |
CVE-2026-4387: CWE-312 Cleartext Storage of Sensitive Information in StrongDM StrongDM Desktop ApplicationCVE-2026-4387 0 StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS permissions. Exploitation requires local read access to the affected user's profile directory and additional deployment and execution conditions on the target host. The condition was reported through coordinated disclosure by Hope Walker (SpecterOps). Join the discussion | CVE Database V5 | 05/29/2026, 18:28:00 UTC Added: 05/29/2026, 19:18:38 UTC |
Showing 1 to 4 of 4 results