CWE-402Class

Transmission of Private Resources into a New Sphere ('Resource Leak')

Draft in the CWE catalog Β· 22 CVEs mapped

22
CVEs mapped
6.9
Median CVSS
What it is

The product makes resources available to untrusted parties when those resources are only intended to be accessed by the product.

Recent examples
7.1cvss
CVE-2025-67745

Myhoard logs backup encryption key in plain text

⚑ A backup logging blunder can expose your encryption keys! MyHoard versions 1.0.1 through 1.2.9 might accidentally spill critical secrets in their logs β€” like leaving the front door wide open during a home renovation. πŸ‘πŸ’” Think of MyHoard as a vault that stores your valuable documents. If that vault logs the combination on a sticky note and leaves it out in the open, anyone could waltz in and take what they want! This oversight could lead to an attacker accessing your MySQL backups and sensitive data β€” with your encryption keys laid bare, they could decrypt everything and wreak havoc. Imagine losing your most critical information because someone snooped at those logs!

HIGH
0%
epss
4.3cvss
CVE-2025-66422

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information

Tryton trytond before 7.6.11 allows remote attackers to obtain sensitive trace-back (server setup) information. This is fixed in 7.6.11, 7.4.21, 7.0.40, and 6.0.70.

MEDIUMno explanation yet
0%
epss
4.7cvss
CVE-2025-55014

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and…

The YouDao plugin for StarDict, as used in stardict 3.0.7+git20220909+dfsg-6 in Debian trixie and elsewhere, sends an X11 selection to the dict.youdao.com and dict.cn servers via cleartext HTTP.

MEDIUMno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-402
Abstraction
Class
Structure
Simple
Status
Draft