Back to Labs
Weakness (CWE)

CWE-312

Cleartext Storage of Sensitive Information

About

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Common consequences

  • Confidentiality → Read Application Data

Mitigations

  • Implementation, System Configuration, Operation: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest. [REF-1297] [REF-1299] [REF-1301]
  • Implementation, System Configuration, Operation: In some systems/environments such as cloud, the use of "double encryption" (at both the software and hardware layer) might be required, and the developer might be solely responsible for both layers, instead of shared responsibility with the administrator of the broader system/environment.

CVEs with this weakness

Frequently asked questions

What is CWE-312?

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere. Common consequences Confidentiality → Read Application Data Mitigations Implementation, System Configuration, Operation: When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to encrypt the data at rest.

Which platforms does CWE-312 affect?

CWE-312 has been observed on: Cloud Computing, ICS/OT, Mobile.

How many CVEs does Rainforest track for CWE-312?

Rainforest Labs currently tracks 1 published CVEs mapped to CWE-312. They are listed on this page.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.