目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-312 敏感数据的明文存储 类漏洞列表 311

CWE-312 敏感数据的明文存储 类弱点 311 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-312指敏感信息以明文形式存储在可能被其他控制域访问的资源中。攻击者常通过直接读取配置文件、日志或数据库文件窃取凭证等关键数据。开发者应避免此类风险,采用强加密算法对静态数据进行加密存储,严格限制文件访问权限,并定期审查数据存储逻辑,确保敏感信息仅在必要时以密文形式保留,从而防止未授权访问。

MITRE CWE 官方描述
CWE:CWE-312 敏感信息的明文存储 英文:产品将敏感信息以明文形式存储在可能被其他控制域(control sphere)访问的资源中。
常见影响 (1)
Confidentiality Read Application Data
An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
缓解措施 (2)
Implementation, System Configuration, Operation When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
Implementation, System Configuration, Operation In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.
代码示例 (2)
The following code excerpt stores a plaintext user account ID in a browser cookie.
response.addCookie( new Cookie("userAccountID", acctID);
Bad · Java
This code writes a user's login information to a cookie so the user does not have to login again later.
function persistLogin($username, $password){ $data = array("username" => $username, "password"=> $password); setcookie ("userdata", $data); }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2024-31415 Eaton Foreseer EPMS 安全漏洞 — Foreseer 6.3 Medium 2024-09-13
CVE-2024-8689 Palo Alto Networks Cortex Xsoar 安全漏洞 — ActiveMQ Content Pack 7.5AI High AI 2024-09-11
CVE-2024-6921 NAC Telecommunication NACPremium 安全漏洞 — NACPremium 7.5AI High AI 2024-09-02
CVE-2021-22509 NetIQ Advanced Authentication 安全漏洞 — NetIQ Advance Authentication 8.1 High 2024-08-28
CVE-2024-38877 Siemens多款产品 安全漏洞 — Omnivise T3000 Application Server R9.2 8.2 High 2024-08-02
CVE-2024-41691 SyroTech SY-GPON-1110-WDONT 安全漏洞 — SyroTech SY-GPON-1110-WDONT router 6.8 - 2024-07-26
CVE-2024-41690 SyroTech SY-GPON-1110-WDONT 安全漏洞 — SyroTech SY-GPON-1110-WDONT router 6.4 - 2024-07-26
CVE-2024-41688 SyroTech SY-GPON-1110-WDONT 安全漏洞 — SyroTech SY-GPON-1110-WDONT router 6.8 - 2024-07-26
CVE-2024-39674 Huawei EMUI和Huawei HarmonyOS 安全漏洞 — HarmonyOS 6.2 Medium 2024-07-25
CVE-2024-25023 IBM Cloud Pak for Security 安全漏洞 — QRadar Suite Software 5.5 Medium 2024-07-09
CVE-2024-29954 Brocade Fabric OS 安全漏洞 — Fabric OS 5.9 Medium 2024-06-25
CVE-2024-36497 Faronics WINSelect 安全漏洞 — WINSelect (Standard + Enterprise) 7.7AI High AI 2024-06-24
CVE-2023-49113 Kiuwan SAST 跨站脚本漏洞 — SAST Local Analyzer 7.5 - 2024-06-20
CVE-2024-28024 Hitachi FOXMAN-UN 安全漏洞 — FOXMAN-UN 4.1 Medium 2024-06-11
CVE-2024-4540 Red Hat Keycloak 信息泄露漏洞 7.5 High 2024-06-03
CVE-2024-36119 Statamic CMS 安全漏洞 — cms 1.8 Low 2024-05-30
CVE-2024-31486 Siemens OPUPI0 安全漏洞 — OPUPI0 AMQP/MQTT 5.3 Medium 2024-05-14
CVE-2024-4840 Red Hat OpenStack Platform 安全漏洞 5.5 Medium 2024-05-13
CVE-2023-27370 NETGEAR RAX30 安全漏洞 — RAX30 5.7 - 2024-05-03
CVE-2024-4235 NETGEAR DG834G 安全漏洞 — DG834Gv5 2.7 Low 2024-04-26
CVE-2024-3742 Electrolink FM/DAB/TV Transmitter 安全漏洞 — Compact DAB Transmitter 7.5 High 2024-04-18
CVE-2024-32474 Mobileiron Sentry 安全漏洞 — sentry 7.3 High 2024-04-18
CVE-2024-29956 Broadcom Brocade SANnav 安全漏洞 — Brocade SANnav 6.5 Medium 2024-04-18
CVE-2024-29952 Broadcom Brocade SANnav 安全漏洞 — Brocade SANnav 5.5 Medium 2024-04-17
CVE-2023-50957 IBM Storage Defender 安全漏洞 — Storage Defender - Resiliency Service 8.0 High 2024-02-10
CVE-2023-6874 Silicon Labs EmberZNet 安全漏洞 — GSDK 7.5 High 2024-02-05
CVE-2023-5384 Red Hat Infinispan 安全漏洞 — Red Hat Data Grid 8.4.6 7.2 High 2023-12-18
CVE-2023-48707 CodeIgniter Shield 安全漏洞 — shield 5.0 Medium 2023-11-24
CVE-2023-48305 Nextcloud 安全漏洞 — security-advisories 4.2 Medium 2023-11-21
CVE-2023-41096 Silicon Labs OpenThread SDK 安全漏洞 — Ember ZNet SDK 6.8 Medium 2023-10-26

CWE-312(敏感数据的明文存储) 是常见的弱点类别,本平台收录该类弱点关联的 311 条 CVE 漏洞。