← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Barracuda
1Load Balancer Adc Firmware
Jun 17, 2026
Mar 12, 2020
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-control...Show more
Authenticated, administrative access to a Barracuda Load Balancer ADC running unpatched firmware <= v6.4 allows one to edit the LDAP service configuration of the balancer and change the LDAP server to an attacker-controlled system, without having to re-enter LDAP credentials. These steps can be used by any authenticated administrative user to expose the LDAP credentials configured in the LDAP connector over the network.Show less
1Moxa
6Mb3170 Firmware
Mb3180 FirmwareMb3270 Firmware+3 more
Jun 17, 2026
Mar 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains pa...Show more
An issue was discovered on Moxa MGate MB3170 and MB3270 devices before 4.1, MB3280 and MB3480 devices before 3.1, MB3660 devices before 2.3, and MB3180 devices before 2.1. The application's configuration file contains parameters that represent passwords in cleartext.Show less
1Westerndigital
20Sandisk X600 Sd9sb8w 128g Firmware
Sandisk X600 Sd9sb8w 1t00 FirmwareSandisk X600 Sd9sb8w 256g Firmware+17 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Western Digital SanDisk X600 devices in certain configurations, a vulnerability in the access control mechanism of the drive may allow data to be decrypted without knowledge of proper authentication credentials.
1Westerndigital
59Sandisk X300 Sd7sb6s 128g Firmware
Sandisk X300 Sd7sb6s 256g FirmwareSandisk X300 Sd7sb7s 010t Firmware+56 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the dr...Show more
Western Digital SanDisk X300, X300s, X400, and X600 devices: A vulnerability in the wear-leveling algorithm of the drive may cause cryptographically sensitive parameters (such as data encryption keys) to remain on the drive media after their intended erasure.Show less
1Westerndigital
59Sandisk X300 Sd7sb6s 128g Firmware
Sandisk X300 Sd7sb6s 256g FirmwareSandisk X300 Sd7sb7s 010t Firmware+56 more
Jun 17, 2026
Mar 10, 2020
N/A· v4
6.3 MEDIUM· v3
6.3 MEDIUM· v2
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the...Show more
Western Digital SanDisk SanDisk X300, X300s, X400, and X600 devices: The firmware update authentication method relies on a symmetric HMAC digest. The key used to validate this digest is present in a protected area of the device, and if extracted could be used to install arbitrary firmware to other devices.Show less
1Jenkins
1Zephyr Enterprise Test Management
Jun 17, 2026
Mar 9, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
2Broadcom
Pivotal
2Reactor Netty
Reactor Netty
Sep 4, 2026
Mar 3, 2020
N/A· v4
5.9 MEDIUM· v3
4.9 MEDIUM· v2
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to h...Show more
The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a different domain. In order for this to happen, the HttpClient must have been explicitly configured to follow redirects.Show less
2Canonical
Mozilla
2Thunderbird
Ubuntu Linux
Jun 17, 2026
Mar 2, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the da...Show more
If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Thunderbird 60. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Thunderbird < 68.5.Show less
1Apple
3Ipados
Iphone OsSafari
Jun 17, 2026
Feb 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
The issue was addressed with improved UI handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, Safari 13.0.5. A local user may unknowingly send a password unencrypted over the network.
1Cloudfoundry
2Capi Release
Cf Deployment
Jun 17, 2026
Feb 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user...Show more
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.Show less
1Redhat
1Ansible
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@s...Show more
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.Show less
1Redhat
1Ansible
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumsta...Show more
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.Show less
1Jenkins
1Applatix
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Parasoft Environment Manager
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the mas...Show more
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Harvest Scm
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system...Show more
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Harvest Scm
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Eagle Tester
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Ecx Copy Data Management
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master f...Show more
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Bmc Release Package And Deployment
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sys...Show more
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.Show less
1Jenkins
1Digitalocean
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.