目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-312 敏感数据的明文存储 类漏洞列表 311

CWE-312 敏感数据的明文存储 类弱点 311 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-312指敏感信息以明文形式存储在可能被其他控制域访问的资源中。攻击者常通过直接读取配置文件、日志或数据库文件窃取凭证等关键数据。开发者应避免此类风险,采用强加密算法对静态数据进行加密存储,严格限制文件访问权限,并定期审查数据存储逻辑,确保敏感信息仅在必要时以密文形式保留,从而防止未授权访问。

MITRE CWE 官方描述
CWE:CWE-312 敏感信息的明文存储 英文:产品将敏感信息以明文形式存储在可能被其他控制域(control sphere)访问的资源中。
常见影响 (1)
Confidentiality Read Application Data
An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
缓解措施 (2)
Implementation, System Configuration, Operation When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
Implementation, System Configuration, Operation In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.
代码示例 (2)
The following code excerpt stores a plaintext user account ID in a browser cookie.
response.addCookie( new Cookie("userAccountID", acctID);
Bad · Java
This code writes a user's login information to a cookie so the user does not have to login again later.
function persistLogin($username, $password){ $data = array("username" => $username, "password"=> $password); setcookie ("userdata", $data); }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2023-41095 Silicon Labs OpenThread SDK 安全漏洞 — OpenThread SDK 6.8 Medium 2023-10-26
CVE-2023-45151 Nextcloud 安全漏洞 — security-advisories 6.5 Medium 2023-10-16
CVE-2023-41964 F5 BIG-IP 安全漏洞 — BIG-IP 4.3 Medium 2023-10-10
CVE-2023-2809 Sage 200c 安全漏洞 — Sage 200 Spain 7.8 High 2023-10-04
CVE-2023-44159 Acronis Cyber Protect 安全漏洞 — Acronis Cyber Protect 15 7.5 - 2023-09-27
CVE-2023-41335 Synapse 安全漏洞 — synapse 3.7 Low 2023-09-26
CVE-2023-40715 FortiTester 安全漏洞 — FortiTester 5.2 Medium 2023-09-13
CVE-2023-3950 GitLab 安全漏洞 — GitLab 5.5 Medium 2023-09-01
CVE-2023-31423 Broadcom Brocade SANnav 安全漏洞 — SANnav 5.7 Medium 2023-08-31
CVE-2023-31925 Brocade SANnav 安全漏洞 — Brocade SANnav 5.4 Medium 2023-08-31
CVE-2023-3489 Brocade Fabric OS 安全漏洞 — Fabric OS 8.6 High 2023-08-30
CVE-2023-4392 Control iD Gerencia Web 安全漏洞 — Gerencia Web 3.7 Low 2023-08-17
CVE-2023-39210 Zoom Client 安全漏洞 — Zoom Client SDK for Windows 5.5 Medium 2023-08-08
CVE-2023-39440 SAP BusinessObjects Business Intelligence 信息泄露漏洞 — SAP BusinessObjects Business Intelligence 4.4 Medium 2023-08-08
CVE-2023-32447 Dell Wyse ThinOS 日志信息泄露漏洞 — Wyse Proprietary OS (Modern ThinOS) 5.5 Medium 2023-07-20
CVE-2023-32446 Dell Wyse ThinOS 日志信息泄露漏洞 — Wyse Proprietary OS (Modern ThinOS) 5.5 Medium 2023-07-20
CVE-2023-32455 Dell Wyse ThinOS 日志信息泄露漏洞 — Wyse Proprietary OS (Modern ThinOS) 5.5 Medium 2023-07-20
CVE-2023-32483 Dell Wyse Management Suite 安全漏洞 — Wyse Management Suite 4.4 Medium 2023-07-20
CVE-2023-37468 Feedbacksystem 安全漏洞 — feedbacksystem 6.0 Medium 2023-07-13
CVE-2022-22302 Fortinet FortiOS和FortiAuthenticator 安全漏洞 — FortiAuthenticator 5.3 Medium 2023-07-11
CVE-2023-22584 Danfoss AK-EM100 web applications 安全漏洞 — AK-EM100 7.5 High 2023-06-11
CVE-2023-32448 Dell PowerPath Management Appliance 安全漏洞 — PowerPath Windows 5.5 Medium 2023-05-30
CVE-2023-31408 SICK FTMg 安全漏洞 — SICK FTMG-ESD15AXX AIR FLOW SENSOR 5.3 Medium 2023-05-15
CVE-2023-24964 IBM InfoSphere Information Server 安全漏洞 — InfoSphere Information Server 6.2 Medium 2023-02-17
CVE-2022-45154 SUSE Linux Enterprise Server 安全漏洞 — SUSE Linux Enterprise Server 12 4.4 Medium 2023-02-15
CVE-2023-0690 HashiCorp Boundary 安全漏洞 — Boundary 5.0 Medium 2023-02-08
CVE-2022-43757 Rancher 安全漏洞 — Rancher 9.9 Critical 2023-02-07
CVE-2023-23944 Nextcloud 安全漏洞 — security-advisories 2.0 Low 2023-02-06
CVE-2022-38112 Database Performance Analyzer 安全漏洞 — Database Performance Analyzer (DPA) 7.5 High 2023-01-20
CVE-2022-45439 Zyxel AX7501-B0 安全漏洞 — AX7501-B0 firmware 6.5 Medium 2023-01-17

CWE-312(敏感数据的明文存储) 是常见的弱点类别,本平台收录该类弱点关联的 311 条 CVE 漏洞。