目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-312 敏感数据的明文存储 类漏洞列表 311

CWE-312 敏感数据的明文存储 类弱点 311 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-312指敏感信息以明文形式存储在可能被其他控制域访问的资源中。攻击者常通过直接读取配置文件、日志或数据库文件窃取凭证等关键数据。开发者应避免此类风险,采用强加密算法对静态数据进行加密存储,严格限制文件访问权限,并定期审查数据存储逻辑,确保敏感信息仅在必要时以密文形式保留,从而防止未授权访问。

MITRE CWE 官方描述
CWE:CWE-312 敏感信息的明文存储 英文:产品将敏感信息以明文形式存储在可能被其他控制域(control sphere)访问的资源中。
常见影响 (1)
Confidentiality Read Application Data
An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
缓解措施 (2)
Implementation, System Configuration, Operation When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
Implementation, System Configuration, Operation In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.
代码示例 (2)
The following code excerpt stores a plaintext user account ID in a browser cookie.
response.addCookie( new Cookie("userAccountID", acctID);
Bad · Java
This code writes a user's login information to a cookie so the user does not have to login again later.
function persistLogin($username, $password){ $data = array("username" => $username, "password"=> $password); setcookie ("userdata", $data); }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-100288 Devolutions Server 2026.3.5.0及更早版本明文存储敏感信息漏洞 — Server - - 2026-09-29
CVE-2026-100862 heym 0.0.91 多个密钥明文存储漏洞 — heym 4.9 Medium 2026-09-27
CVE-2026-100581 OpenClaw iOS 凭证通过共享扩展存储漏洞 — OpenClaw 5.5 Medium 2026-09-26
CVE-2026-67236 RabbitMQ 登录后明文凭据存储在不安全 Cookie 中 — rabbitmq-server 8.2 High 2026-09-25
CVE-2026-67221 RabbitMQ AMQP 1.0 明文URI密码泄露 — rabbitmq-server 5.9 Medium 2026-09-23
CVE-2026-96549 hosp_order CommonUserServiceImpl.java 明文存储漏洞 — hosp_order 3.3 Low 2026-09-23
CVE-2026-77250 Atlassian MCP 令牌明文存储漏洞 — mcp-atlassian 6.1 Medium 2026-09-22
CVE-2026-93763 数据库未解析调用名致加密明文持久化漏洞 — Mongoid 6.5 Medium 2026-09-18
CVE-2026-93764 加密字段明文存储漏洞 — Mongoid 6.5 Medium 2026-09-18
CVE-2026-63406 AnyCable 遥测子系统硬编码认证令牌漏洞 — anycable 5.9 Medium 2026-09-18
CVE-2026-81321 CareCam CM2507 敏感信息明文存储漏洞 — HMT.CM2507 Firmware 9.8 Critical 2026-09-18
CVE-2026-44940 SUSE Observability 服务令牌暴露与提权漏洞 — SUSE Observability 5.7 Medium 2026-09-17
CVE-2026-86443 敏感信息明文存储漏洞 — DuoxMe 6.9 Medium 2026-09-16
CVE-2026-4130 NI systemlink 加密问题漏洞 — SystemLink 7.1 High 2026-09-10
CVE-2026-80058 Dell Secure Connect Gateway 加密问题漏洞 — Secure Connect Gateway 5.0 - Application 5.5 Medium 2026-09-07
CVE-2026-86280 SourceCodester Syllabus-Aligned Learning Management & Examination System 加密问题漏洞 — Syllabus-Aligned Learning Management & Examination System 5.3 Medium 2026-09-07
CVE-2026-53603 Forgekeep nebula-mesh 加密问题漏洞 — nebula-mesh 7.1 High 2026-09-04
CVE-2026-83551 Amazon SageMaker Python SDK 加密问题漏洞 — sagemaker-python-sdk 7.2 High 2026-09-01
CVE-2026-77975 Ebyte NE2-D11 加密问题漏洞 — Ebyte NE2-D11 Firmware 6.5 Medium 2026-08-31
CVE-2026-82699 sambitraj Student Management System 加密问题漏洞 — Student Management System 2.7 Low 2026-08-31
CVE-2026-82640 Browser Use Web UI 加密问题漏洞 — web-ui 5.5 Medium 2026-08-30
CVE-2026-77970 Ash Framework AshPaperTrail 加密问题漏洞 — ash_paper_trail 5.9 Medium 2026-08-30
CVE-2026-75847 Ash Framework AshPaperTrail 加密问题漏洞 — ash_paper_trail 5.9 Medium 2026-08-30
CVE-2026-81683 Tobi OpenSSL Encrypt 加密问题漏洞 — openssl_encrypt 8.4 High 2026-08-27
CVE-2026-59657 Apache CloudStack 加密问题漏洞 — Apache CloudStack - - 2026-08-21
CVE-2026-76405 Splunk On-Call (VictorOps) 加密问题漏洞 — Splunk On-Call (VictorOps) 4.3 Medium 2026-08-19
CVE-2026-76386 Splunk SOAR 加密问题漏洞 — Zoom app for Splunk SOAR 4.3 Medium 2026-08-19
CVE-2026-76384 Splunk Attack Analyzer Connector for Splunk SOAR 加密问题漏洞 — Splunk Attack Analyzer Connector for Splunk SOAR 4.3 Medium 2026-08-19
CVE-2026-76385 Splunk SOAR 加密问题漏洞 — Venafi app for Splunk SOAR 4.3 Medium 2026-08-19
CVE-2026-76383 Splunk RSA SecurID Authentication Manager app for Splunk SOAR 加密问题漏洞 — RSA SecurID Authentication Manager app for Splunk SOAR 4.3 Medium 2026-08-19

CWE-312(敏感数据的明文存储) 是常见的弱点类别,本平台收录该类弱点关联的 311 条 CVE 漏洞。