CWE Database
/

CWE-214

Back to CWE list

CWE-214

Invocation of Process Using Visible Sensitive Information

Base
Incomplete

Description

A process is invoked with sensitive command-line arguments, environment variables, or other elements that can be seen by other processes on the operating system.

Many operating systems allow a user to list information about processes that are owned by other users. Other users could see information such as command line arguments or environment variable settings. When this data contains sensitive information such as credentials, it might allow other users to launch an attack against the product or related resources.

Common Consequences

Scope

Confidentiality

Impact

Read Application Data

CVE-2023-38994

IAM product includes LDAP password in a process call, allowing local users to obtain the password

CVE-2005-1387

password passed on command line

CVE-2005-2291

password passed on command line

CVE-2001-1565

username/password on command line allows local users to view via "ps" or other process listing programs

CVE-2004-1948

Username/password on command line allows local users to view via "ps" or other process listing programs.

CVE-1999-1270

PGP passphrase provided as command line argument.

CVE-2004-1058

Kernel race condition allows reading of environment variables of a process that is still spawning.

CVE-2021-32638

Code analysis product passes access tokens as a command-line parameter or through an environment variable, making them visible to other processes via the ps command.

Applicable Platforms

Not Language-Specific

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now