Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated local user with read access to the registry can extract these sensitive values.
Metrics
Affected Vendors & Products
References
History
Thu, 24 Jul 2025 13:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 24 Jul 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Lack of sensitive data encryption in CapillaryScope v2.5.0 of Capillary io, which stores both the proxy credentials and the JWT session token in plain text within different registry keys on the Windows operating system. Any authenticated local user with read access to the registry can extract these sensitive values. | |
Title | Encryption of sensitive data in CapillaryScope missing | |
Weaknesses | CWE-311 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: INCIBE
Published: 2025-07-24T12:14:20.971Z
Updated: 2025-07-24T13:01:30.427Z
Reserved: 2025-04-16T08:38:16.029Z
Link: CVE-2025-40680

Updated: 2025-07-24T13:01:27.966Z

Status : Awaiting Analysis
Published: 2025-07-24T13:15:25.843
Modified: 2025-07-25T15:29:19.837
Link: CVE-2025-40680

No data.