← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
27Anynines
ApigeeAppdynamics+24 more
55Application Analytics
Application MonitoringApplication Performance Monitoring+52 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.Show less
1Jenkins
1Skytap Cloud Ci
Jun 17, 2026
Jul 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file...Show more
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1M2release
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Configuration As Code
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
1Kolide
1Fleet
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fleet before 2.1.2 allows exposure of SMTP credentials.
1Jenkins
1Credentials Binding
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly lin...Show more
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.Show less
1Rdbrck
1Shift
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
1Aquaverde
1Aquarius Cms
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The componen...Show more
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.Show less
1Alarm
1Adc V522ir Firmware
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.co...Show more
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.Show less
1Jenkins
1Mashup Portlets
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.
1Dropbox
1Dropbox
Jun 17, 2026
Jul 8, 2019
N/A· v4
7.8 HIGH· v3
4.3 MEDIUM· v2
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed i...Show more
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.Show less
1Fortinet
1Fcm Mb40 Firmware
Jun 17, 2026
Jul 8, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fi...Show more
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files....Show more
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files. If the Settings Repository plugin was then used and configured to synchronize IDE settings using a public repository, these credentials were published to this repository. The issue has been fixed in the following versions: 2019.1, 2018.3.5, 2018.2.8, and 2018.1.8.Show less
1Jetbrains
1Intellij Idea
Jun 17, 2026
Jul 3, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has bee...Show more
In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the IDE configuration files. The issue has been fixed in the following versions: 2018.3.5, 2018.2.8, 2018.1.8.Show less
1Jetbrains
1Hub
Jun 17, 2026
Jul 3, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the aud...Show more
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password has not changed since 2017, and if the audit log still contains events from before that period.Show less
1Calamares
1Calamares
Jun 17, 2026
Jul 2, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this o...Show more
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with insecure permissions, which allows this originally protected file to be read by any user, thereby disclosing decryption keys for LUKS containers created with Full Disk Encryption.Show less
1Nortekcontrol
2Linear Emerge Elite Firmware
Linear Emerge Essential Firmware
Jun 17, 2026
Jul 2, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
1Nortekcontrol
2Linear Emerge 5000p Firmware
Linear Emerge 50p Firmware
Jun 17, 2026
Jul 1, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
1Logitech
1R500 Firmware
Jun 17, 2026
Jun 29, 2019
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters...Show more
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to bypass the restriction on the characters A through Z.Show less