CWE-319
923 CVEs • Abstraction: Base • Likelihood of Exploit: High
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CVEs (923)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Inedo ProGet Plugin 1.2 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. |
Jenkins Inedo BuildMaster Plugin 2.4.0 and earlier transmitted configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure. |
1Netapp 1Ontap Select Deploy Administration Utility Jun 17, 2026 Sep 24, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 ONTAP Select Deploy administration utility versions 2.2 through 2.12.1 transmit credentials in plaintext. |
An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pressing the "Save and test" button within a...Show more |
1Jenkins 1Aqua Security Severless Scanner Jun 17, 2026 Sep 12, 2019 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 Jenkins Aqua Security Serverless Scanner Plugin 1.0.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. |
1Netapp 1Oncommand Workflow Automation Jun 17, 2026 Sep 10, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 OnCommand Workflow Automation versions prior to 5.0 shipped without certain HTTP Security headers configured which could allow an attacker to obtain sensitive information via unspecified vectors. |
The TikTok (formerly Musical.ly) application 12.2.0 for Android and iOS performs unencrypted transmission of images, videos, and likes. This allows an attacker to extract private sensitive information by sniffing network...Show more |
1Jenkins 1Ibm Application Security On Cloud Jun 17, 2026 Aug 28, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Jenkins IBM Application Security on Cloud Plugin 1.2.4 and earlier transmitted configured passwords in plain text as part of job configuration forms, potentially resulting in their exposure. |
1Belwith Keeler 1Hickory Smart Ethernet Bridge Firmware Jun 17, 2026 Aug 22, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A cleartext transmission of sensitive information vulnerability is present in Hickory Smart Ethernet Bridge from Belwith Products, LLC. Captured data reveals that the Hickory Smart Ethernet Bridge device communicates ove...Show more |
1Pivotal Software 1Application Service Jun 17, 2026 Aug 19, 2019 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via S...Show more |
The handshake protocol in Object Management Group (OMG) DDS Security 1.1 sends cleartext information about all of the capabilities of a participant (including capabilities inapplicable to the current session), which make...Show more |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 SAP BusinessObjects Business Intelligence Platform (Web Intelligence), versions 4.1, 4.2, can access database with unencrypted connection, even if the quality of protection should be encrypted. |
1Sap 1Businessobjects Business Intelligence Jun 17, 2026 Aug 14, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Unencrypted communication error in SAP Business Objects Business Intelligence Platform (Central Management Console), version 4.2, leads to disclosure of list of user names and roles imported from SAP NetWeaver BI systems...Show more |
2Enigmail Fedoraproject2Enigmail FedoraJun 17, 2026 Aug 5, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters...Show more |
1Jenkins 1Configuration As Code Jun 17, 2026 Jul 31, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Configuration as Code Plugin 1.24 and earlier did not reliably identify sensitive values expected to be exported in their encrypted form. |
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network. |
1Oneidentity 1Cloud Access Manager Jun 17, 2026 Jul 29, 2019 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 One Identity Cloud Access Manager 8.1.3 does not use HTTP Strict Transport Security (HSTS), which may allow man-in-the-middle (MITM) attacks. This issue is fixed in version 8.1.4. |
A vulnerability was found in the app 2.0 of the Shenzhen Jisiwei i3 robot vacuum cleaner. Actions performed on the app such as changing a password, and personal information it communicates with the server, use unencrypte...Show more |
JetBrains Ktor framework (created using the Kotlin IDE template) versions before 1.1.0 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. This issue was fixed...Show more |
JetBrains Kotlin versions before 1.3.30 were resolving artifacts using an http connection during the build process, potentially allowing an MITM attack. |