目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-312 敏感数据的明文存储 类漏洞列表 311

CWE-312 敏感数据的明文存储 类弱点 311 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-312指敏感信息以明文形式存储在可能被其他控制域访问的资源中。攻击者常通过直接读取配置文件、日志或数据库文件窃取凭证等关键数据。开发者应避免此类风险,采用强加密算法对静态数据进行加密存储,严格限制文件访问权限,并定期审查数据存储逻辑,确保敏感信息仅在必要时以密文形式保留,从而防止未授权访问。

MITRE CWE 官方描述
CWE:CWE-312 敏感信息的明文存储 英文:产品将敏感信息以明文形式存储在可能被其他控制域(control sphere)访问的资源中。
常见影响 (1)
Confidentiality Read Application Data
An attacker with access to the system could read sensitive information stored in cleartext (i.e., unencrypted). Even if the information is encoded in a way that is not human-readable, certain techniques could determine which encoding is being used, then decode the information.
缓解措施 (2)
Implementation, System Configuration, Operation When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
Implementation, System Configuration, Operation In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.
代码示例 (2)
The following code excerpt stores a plaintext user account ID in a browser cookie.
response.addCookie( new Cookie("userAccountID", acctID);
Bad · Java
This code writes a user's login information to a cookie so the user does not have to login again later.
function persistLogin($username, $password){ $data = array("username" => $username, "password"=> $password); setcookie ("userdata", $data); }
Bad · PHP
CVE ID 标题 CVSS 风险等级 Published
CVE-2022-42284 NVIDIA BMC 安全漏洞 — NVIDIA DGX servers 6.2 Medium 2023-01-13
CVE-2022-45787 Apache James 信息泄露漏洞 — Apache James MIME4J 5.5 - 2023-01-06
CVE-2022-47512 SolarWinds Platform 安全漏洞 — Hybrid Cloud Observability (HCO)/ SolarWinds Platform 5.5 Medium 2022-12-21
CVE-2022-4312 ARC Informatique PcVue 安全漏洞 — PcVue 5.5 Medium 2022-12-12
CVE-2022-29826 Mitsubishi Electric GX Works3 安全漏洞 — GX Works3 6.8 Medium 2022-11-24
CVE-2022-25164 Mitsubishi Electric GX Works3 安全漏洞 — GX Works3 8.6 High 2022-11-24
CVE-2022-41933 XWiki Platform 安全漏洞 — xwiki-platform 6.2 Medium 2022-11-23
CVE-2022-2513 Hitachi Energy PCM600 安全漏洞 — PCM600 7.1 High 2022-11-22
CVE-2022-39364 Nextcloud 安全漏洞 — security-advisories 4.0 Medium 2022-10-27
CVE-2022-39351 Dependency-Track 安全漏洞 — dependency-track 4.4 Medium 2022-10-25
CVE-2022-2805 ovirt-engine 信息泄露漏洞 — ovirt-engine 5.5 - 2022-10-19
CVE-2022-32217 Rocket.Chat 日志信息泄露漏洞 — Rocket.chat 5.3 - 2022-09-23
CVE-2021-36782 Rancher Labs Rancher 安全漏洞 — Rancher 9.9 Critical 2022-09-07
CVE-2022-2569 ARC Informatique PcVue 安全漏洞 — PcVue 12 OAuth web service configuration 5.5 Medium 2022-08-24
CVE-2022-2813 Guest Management System 安全漏洞 — Guest Management System 4.3 Medium 2022-08-14
CVE-2017-20040 SICUNET Access Controller 安全漏洞 — Access Controller 5.9 Medium 2022-06-11
CVE-2022-28214 SAP Business Objects 安全漏洞 — SAP BusinessObjects Enterprise (Central Management Server) 7.8 - 2022-05-11
CVE-2021-35036 Zyxel NWA-1100-NH 命令注入漏洞 — VMG3625-T50B firmware 6.5 Medium 2022-03-01
CVE-2020-14480 Rockwell Automation FactoryTalk View SE 安全漏洞 — FactoryTalk View SE 7.1 - 2022-02-24
CVE-2021-3551 PKI-server 安全漏洞 — pki-server 7.8 - 2022-02-16
CVE-2022-21818 Nvidia License System 安全漏洞 — NVIDIA License System 5.4 Medium 2022-02-14
CVE-2022-20660 Cisco IP Phone 安全漏洞 — Cisco Session Initiation Protocol (SIP) Software 4.6 Medium 2022-01-14
CVE-2021-35035 Zyxel NBG6604 信息泄露漏洞 — NBG6604 series firmware 4.9 Medium 2021-12-29
CVE-2021-42066 SAP Business One 安全漏洞 — SAP Business One 4.4 - 2021-12-14
CVE-2020-10053 SIMATIC RTLS 安全漏洞 — SIMATIC RTLS Locating Manager 5.5 - 2021-11-09
CVE-2021-38422 Delta Electronics DiaLink 安全漏洞 — DIALink 7.8 High 2021-11-03
CVE-2021-33716 Siemens SIMATIC CP 1543-1和SIMATIC CP 1545-1 安全漏洞 — SIMATIC CP 1543-1 (incl. SIPLUS variants) 6.5 - 2021-09-14
CVE-2021-22929 Brave 日志信息泄露漏洞 — https://github.com/brave/brave-core 2.8 - 2021-08-31
CVE-2021-29481 Ratpack 安全漏洞 — ratpack 6.5 Medium 2021-06-29
CVE-2021-27487 ZOLL Defibrillator Dashboard 安全漏洞 — ZOLL Defibrillator Dashboard 5.5 - 2021-06-16

CWE-312(敏感数据的明文存储) 是常见的弱点类别,本平台收录该类弱点关联的 311 条 CVE 漏洞。