CVEbaza.plSłownik CWECWE-214
Common Weakness Enumeration

CWE-214

Invocation of Process Using Visible Sensitive Information

Kategoria: BaseCVE: 28
Opis

Proces jest wywoływany z wrażliwymi argumentami wiersza poleceń, zmiennymi środowiskowymi lub innymi elementami, które mogą być widoczne dla innych procesów w systemie operacyjnym. Stanowi to zagrożenie bezpieczeństwa, ponieważ poufne dane mogą zostać ujawnione innym użytkownikom lub procesom działającym na komputerze.

Description (EN)

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Podatności CVE z CWE-214 (28)
8.7
CVSS
HIGH
CVE-2026-74873

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Attackers can read process arguments through ps aux or /proc/[pid]/cmdline to retrieve plaintext passwords and keystore passwords.

pub. 2026-08-17
7.9
CVSS
HIGH
CVE-2026-12250

Podatność w aplikacji Pardus Domain Joiner (TUBITAK BILGEM) polega na przekazywaniu wrażliwych informacji w sposób widoczny podczas wywoływania procesu systemowego. Umożliwia to lokalnym użytkownikom pozyskanie danych uwierzytelniających lub innych poufnych informacji.

pub. 2026-07-05
7.8
CVSS
HIGH
CVE-2020-36771

CloudLinux CageFS 7.1.1-1 or below passes the authentication token as a command line argument. In some configurations this allows local users to view the authentication token via the process list and gain code execution as another user.

pub. 2024-01-22
7.8
CVSS
HIGH
CVE-2018-16837

Ansible "User" module leaks any data which is passed on as a parameter to ssh-keygen. This could lean in undesirable situations such as passphrases credentials passed as a parameter for the ssh-keygen executable. Showing those credentials in clear text form for every user which have access just to the process list.

pub. 2018-10-23
7.5
CVSS
HIGH
CVE-2021-3859

A flaw was found in Undertow that tripped the client-side invocation timeout with certain calls made over HTTP2. This flaw allows an attacker to carry out denial of service attacks.

pub. 2022-08-26
7.4
CVSS
HIGH
CVE-2026-33247

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if that too is enabled. The `/debug/vars` end-point contains an unredacted copy of argv. Versions 2.11.15 and 2.12.6 contain a fix. As a workaround, configure credentials inside a configuration file instead of via argv, and do not enable the monitoring port if using secrets in argv. Best practice remains to not expose the monitoring port to the Internet, or to untrusted network sources.

pub. 2026-03-25
7.2
CVSS
HIGH
CVE-2019-3869

When running Tower before 3.4.3 on OpenShift or Kubernetes, application credentials are exposed to playbook job runs via environment variables. A malicious user with the ability to write playbooks could use this to gain administrative privileges.

pub. 2019-03-28
7.1
CVSS
HIGH
CVE-2026-76054

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an actor able to execute code within the scanned project's build to obtain the Black Duck API token via the ambient process environment, which is inherited by subprocesses launched during build capture and signature scanning. This applies only where the token is supplied through the BLACKDUCK_API_TOKEN or BD_HUB_TOKEN environment variable. Upgrading does not remediate prior disclosure; any token supplied to an affected version through an environment variable should be rotated.

pub. 2026-08-24
7.1
CVSS
HIGH
CVE-2024-4254

The 'deploy-website.yml' workflow in the gradio-app/gradio repository, specifically in the 'main' branch, is vulnerable to secrets exfiltration due to improper authorization. The vulnerability arises from the workflow's explicit checkout and execution of code from a fork, which is unsafe as it allows the running of untrusted code in an environment with access to push to the base repository and access secrets. This flaw could lead to the exfiltration of sensitive secrets such as GITHUB_TOKEN, HF_TOKEN, VERCEL_ORG_ID, VERCEL_PROJECT_ID, COMMENT_TOKEN, AWSACCESSKEYID, AWSSECRETKEY, and VERCEL_TOKEN. The vulnerability is present in the workflow file located at https://github.com/gradio-app/gradio/blob/72f4ca88ab569aae47941b3fb0609e57f2e13a27/.github/workflows/deploy-website.yml.

pub. 2024-06-04
6.6
CVSS
MEDIUM
CVE-2025-5452

A malicious ACAP application can gain access to admin-level service account credentials used by legitimate ACAP applications, leading to potential privilege escalation of the malicious ACAP application. This vulnerability can only be exploited if the Axis device is configured to allow the installation of unsigned ACAP applications, and if an attacker convinces the victim to install a malicious ACAP application.

pub. 2025-11-11
6.5
CVSS
MEDIUM
CVE-2020-5422

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

pub. 2020-10-02
6.0
CVSS
MEDIUM
CVE-2025-1333

IBM MQ Container when used with the IBM MQ Operator LTS 2.0.0 through 2.0.29, MQ Operator CD 3.0.0, 3.0.1, 3.1.0 through 3.1.3, 3.3.0, 3.4.0, 3.4.1, 3.5.0, 3.5.1, and MQ Operator SC2 3.2.0 through 3.2.10 and configured with Cloud Pak for Integration Keycloak could disclose sensitive information to a privileged user.

pub. 2025-05-01
6.0
CVSS
MEDIUM
CVE-2025-32987

Arctera eDiscovery Platform before 10.3.2, when Enterprise Vault Collection Module is used, places a cleartext password on a command line in EVSearcher.

pub. 2025-04-15
5.7
CVSS
MEDIUM
CVE-2025-59955

Coolify to narzędzie open-source do zarządzania serwerami, aplikacjami i bazami danych. W wersjach Coolify poprzedzających i włączając v4.0.0-beta.420.8 luka information disclosure w endpointach API `/api/v1/teams/{team_id}/members` i `/api/v1/teams/current/members` pozwala uwierzytelnionym członkom zespołu na dostęp do wrażliwego `email_change_code` innych użytkowników w tym samym zespole. Ten kod przeznaczony jest do jednorazowej weryfikacji zmiany email i powinien być utajniony — jego ujawnienie mogłoby umożliwić atakującemu nieautoryzowaną zmianę adresu email ofiary. W momencie publikacji nie istnieją znane wersje z poprawką.

pub. 2026-01-05
5.6
CVSS
MEDIUM
CVE-2025-53860

A vulnerability exists in F5OS-A software that allows a highly privileged authenticated attacker to access sensitive FIPS hardware security module (HSM) information on F5 rSeries systems.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

pub. 2025-10-15
5.6
CVSS
MEDIUM
CVE-2024-28799

IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 displays sensitive data improperly to a local privileged user, in non default configurations, during back-end commands which may result in the unexpected disclosure of this information. IBM X-Force ID: 287173.

pub. 2024-08-14
5.5
CVSS
MEDIUM
CVE-2026-65088

NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

pub. 2026-08-25
5.5
CVSS
MEDIUM
CVE-2026-9494

W ubuntu-pro-client firmy Canonical istnieje luka ujawniania informacji. Klient waliduje poświadczenia Ubuntu Pro APT, wykonując /usr/lib/apt/apt-helper za pomocą komendy download-file, podczas czego tajny bearer token jest osadzony bezpośrednio w otwarty tekst jako część URL-a przekazanego przez argumenty wiersza poleceń (argv) w formacie https://bearer:<token>@esm.ubuntu.com/.... Na systemach z domyślnie zmontowanym systemem plików /proc bez włączonych mechanizmów ukrywania procesów (takich jak hidepid), nieprivilegowany attakujący z dostępem lokalnym może monitorować procesy systemowe i odczytać wrażliwy bearer token bezpośrednio z /proc/cmdline podczas działania procesu pomocnika. Wyciekły token może być następnie wykorzystany do nieautoryzowanego dostępu do repozytoriów Ubuntu Pro lub Expanded Security Maintenance (ESM) ofiary.

pub. 2026-07-16
5.5
CVSS
MEDIUM
CVE-2026-40159

PraisonAI to system wieloagentowych zespołów. Przed wersją 4.5.128 integracja MCP (Model Context Protocol) w PraisonAI pozwalała na uruchamianie serwerów w tle za pośrednictwem stdio przy użyciu ciągów poleceń dostarczonych przez użytkownika (np. MCP("npx -y @smithery/cli ...")). Polecenia te są wykonywane przez moduł subprocess Pythona, a implementacja domyślnie przekazuje całe środowisko zmiennych proces macierzystego do spawnu, co powoduje, że każde polecenie MCP dziedziczy wszystkie zmienne środowiskowe, w tym wrażliwe dane takie jak klucze API, tokeny uwierzytelniania i poświadczenia bazy danych. Ryzyko zwiększa się w scenariuszach, gdzie niezaufane lub zewnętrzne pakiety, wywoływane za pośrednictwem runners takich jak npx -y, mogą wykonywać dowolny kod z dostępem do tych zmiennych, umożliwiając tym samym niezamierzoną eksfiltrację poświad

pub. 2026-04-10
5.0
CVSS
MEDIUM
CVE-2026-18915

Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allows System Footprinting. This issue affects eta-otp-lock: before 1.0.4.

pub. 2026-08-06
Pokazano 20 z 28 podatności
Informacje
ID: CWE-214
Typ: Base
Podatności: 28
MITRE CWE ↗
← Słownik CWE