目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-312 敏感数据的明文存储 类漏洞列表 311

CWE-312 敏感数据的明文存储 类弱点 311 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-312指敏感信息以明文形式存储在可能被其他控制域访问的资源中。攻击者常通过直接读取配置文件、日志或数据库文件窃取凭证等关键数据。开发者应避免此类风险,采用强加密算法对静态数据进行加密存储,严格限制文件访问权限,并定期审查数据存储逻辑,确保敏感信息仅在必要时以密文形式保留,从而防止未授权访问。

MITRE CWE 官方描述
CWE:CWE-312 敏感信息的明文存储 英文:产品将敏感信息以明文形式存储在可能被其他控制域(control sphere)访问的资源中。
常见影响 (1)
Confidentiality Read Application Data
An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
缓解措施 (2)
Implementation, System Configuration, Operation When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
Implementation, System Configuration, Operation In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.
代码示例 (2)
The following code excerpt stores a plaintext user account ID in a browser cookie.
response.addCookie( new Cookie("userAccountID", acctID);
Bad · Java
This code writes a user's login information to a cookie so the user does not have to login again later.
function persistLogin($username, $password){ $data = array("username" => $username, "password"=> $password); setcookie ("userdata", $data); }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2025-2189 Tinxy 安全漏洞 — Tinxy Wi-Fi Lock Controller v1 RF 6.8 - 2025-03-11
CVE-2024-10404 Broadcom SANnav 安全漏洞 — Brocade SANnav 5.5 Medium 2025-02-14
CVE-2025-22896 mySCADA myPRO 安全漏洞 — myPRO Manager 8.6 High 2025-02-13
CVE-2025-26495 Salesforce Tableau 安全漏洞 — Tableau Server 7.5 - 2025-02-11
CVE-2024-13843 Ivanti Connect Secure 安全漏洞 — Connect Secure 6.0 Medium 2025-02-11
CVE-2024-53651 Siemens SIPROTEC 5 安全漏洞 — SIPROTEC 5 6MD84 (CP300) 4.6 Medium 2025-02-11
CVE-2024-45718 SolarWinds Kiwi Syslog Server NG 安全漏洞 — Kiwi Syslog NG 4.6 Medium 2025-02-11
CVE-2025-0142 Zoom Jenkins Marketplace plugin 安全漏洞 — Zoom Jenkins Marketplace plugin 4.3 Medium 2025-01-30
CVE-2024-55928 Xerox Workplace Suite 安全漏洞 — Xerox Workplace Suite 6.5 Medium 2025-01-23
CVE-2024-12079 ECOVACS robot lawnmowers 安全漏洞 — Unspecified robots 3.3 Low 2025-01-23
CVE-2025-23027 next-forge 安全漏洞 — next-forge 9.1 - 2025-01-13
CVE-2024-56362 Navidrome 安全漏洞 — navidrome 7.1 High 2024-12-23
CVE-2024-50570 Fortinet FortiClient 安全漏洞 — FortiClientMac 4.9 Medium 2024-12-18
CVE-2024-35117 IBM OpenPages 安全漏洞 — OpenPages with Watson 4.4 Medium 2024-12-11
CVE-2024-12094 Tinxy 安全漏洞 — Tinxy Android app 5.2 - 2024-12-05
CVE-2024-54127 TP-Link Archer C50 安全漏洞 — Archer C50 Wireless Router 4.6 - 2024-12-05
CVE-2024-53979 zhmc-ansible-modules 安全漏洞 — zhmc-ansible-modules 8.3 High 2024-11-29
CVE-2024-53865 zhmcclient 安全漏洞 — python-zhmcclient 8.3 High 2024-11-29
CVE-2024-29146 Sharp MFP 安全漏洞 — Multiple MFPs (multifunction printers) 5.9 Medium 2024-11-26
CVE-2024-52525 Nextcloud 安全漏洞 — security-advisories 1.8 Low 2024-11-15
CVE-2024-51993 Combodo iTop 安全漏洞 — iTop 6.5AI Medium AI 2024-11-07
CVE-2024-10523 TP-LINK IoT Smart Hub 安全漏洞 — TP-Link Tapo H100 IoT Smart Hub 6.1AI Medium AI 2024-11-04
CVE-2024-7783 AnythingLLM 安全漏洞 — mintplex-labs/anything-llm 7.5AI High AI 2024-10-29
CVE-2024-9991 Philips Smart Wi-Fi LED 安全漏洞 — Philips Smart Wi-Fi LED Batten 24-Watt 4.6 - 2024-10-25
CVE-2024-8070 Schneider Electric EVlink Home Smart和Schneider Charge 安全漏洞 — EVlink Home Smart 8.5 High 2024-10-13
CVE-2024-6400 Finrota Netahsilat 安全漏洞 — Netahsilat 7.5 - 2024-10-04
CVE-2024-47529 OpenC3 COSMOS 安全漏洞 — cosmos 5.4 - 2024-10-02
CVE-2024-8459 PLANET switch devices 安全漏洞 — GS-4210-24PL4C hardware 2.0 7.2 High 2024-09-30
CVE-2024-7259 oVirt Node 安全漏洞 4.9 Medium 2024-09-26
CVE-2024-45862 Kastle Access Control System 安全漏洞 — Access Control System 9.8AI Critical AI 2024-09-19

CWE-312(敏感数据的明文存储) 是常见的弱点类别,本平台收录该类弱点关联的 311 条 CVE 漏洞。