The product stores a password in a configuration file that might be accessible to actors who do not know the password.
Avoid storing passwords in easily accessible locations.
Consider storing cryptographic hashes of passwords as an alternative to storing in plaintext.
Our security experts can help you identify and remediate CWE-260 vulnerabilities in your codebase.
Get Security Assessment