CWE-922: Insecure Storage of Sensitive Information
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
How it's found
Insecure Storage of Sensitive Information describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
If read access is not properly restricted, then attackers can steal the sensitive information. If write access is not properly restricted, then attackers can modify and possibly delete the data, causing incorrect results and possibly a denial of service.
Consequences
- Read Application Data, Read Files or Directories: Attackers can read sensitive information by accessing the unrestricted storage mechanism.
- Modify Application Data, Modify Files or Directories: Attackers can overwrite sensitive information by accessing the unrestricted storage mechanism.
How TurboPentest tests for this (white-box)
This weakness (Insecure Storage of Sensitive Information) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 1 rule for it, flagging the issue directly in your source code as part of the pentest.
Frequently asked questions
What is CWE-922?
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
How do you find Insecure Storage of Sensitive Information?
Insecure Storage of Sensitive Information describes a general pattern rather than a single fixed bug. Testers use a mix of static analysis and manual code review to find where a target's code matches this pattern, then confirm exploitability by hand.
What is the impact of CWE-922?
Read Application Data, Read Files or Directories: Attackers can read sensitive information by accessing the unrestricted storage mechanism. Modify Application Data, Modify Files or Directories: Attackers can overwrite sensitive information by accessing the unrestricted storage mechanism.
Does TurboPentest test for Insecure Storage of Sensitive Information?
This weakness (Insecure Storage of Sensitive Information) is caught by white-box static analysis when you connect a GitHub repo: IntegSec's Opengrep SAST rule pack carries 1 rule for it, flagging the issue directly in your source code as part of the pentest.
Related CWEs
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest