Skip to main content

Cleartext Storage in a File or on Disk

CVE-2024-6785

Severity Medium
Score 6.8/10

Summary

The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.

  • LOW
  • LOCAL
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • HIGH
  • NONE

CWE-313 - Cleartext Storage in a File or on Disk

The application stores sensitive information in cleartext in a file, or on disk.

References

Advisory Timeline

  • Published