← Back
CWE-522

1,467 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,467)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Humaxdigital
1Hgb10r 02 Firmware
Jun 17, 2026
Dec 18, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over cleartext HTTP.
1Jenkins
1Weibo
Jun 17, 2026
Dec 17, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Weibo Plugin 1.0.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Redgate Sql Change Automation
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to th...Show more
Jenkins Redgate SQL Change Automation Plugin 2.0.3 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Rundeck
Jun 17, 2026
Dec 17, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission,...Show more
Jenkins Rundeck Plugin 3.6.5 and earlier stores credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
2Redhat
Theforeman
2Hammer Cli
Satellite
Nov 21, 2024
Dec 13, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
1Openstack
1Keystone
Jun 17, 2026
Dec 9, 2019
N/A· v4
8.8 HIGH· v3
3.5 LOW· v2
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Us...Show more
OpenStack Keystone 15.0.0 and 16.0.0 is affected by Data Leakage in the list credentials API. Any user with a role on a project is able to list any credentials with the /v3/credentials API when enforce_scope is false. Users with a role on a project are able to view any other users' credentials, which could (for example) leak sign-on information for Time-based One Time Passwords (TOTP). Deployments with enforce_scope set to false are affected. (There will be a slight performance impact for the list credentials API once this issue is fixed.)Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with...Show more
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Passwords are stored in cleartext and can be read by anyone with access to the device.Show less
1Weidmueller
40Ie Sw Pl08m 6tx 2sc Firmware
Ie Sw Pl08m 6tx 2scs FirmwareIe Sw Pl08m 6tx 2st Firmware+37 more
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
An issue was discovered on Weidmueller IE-SW-VL05M 3.6.6 Build 16102415, IE-SW-VL08MT 3.5.2 Build 16102415, and IE-SW-PL10M 3.3.16 Build 16102416 devices. Sensitive Credentials data is transmitted in cleartext.
2Debian
Stanford
2Debian Linux
Webauth
Nov 21, 2024
Dec 3, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
webauth before 4.6.1 has authentication credential disclosure
1Fedoraproject
1389 Directory Server
Jun 17, 2026
Nov 25, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker...Show more
A flaw has been found in 389-ds-base versions 1.4.x.x before 1.4.1.3. When executed in verbose mode, the dscreate and dsconf commands may display sensitive information, such as the Directory Manager password. An attacker, able to see the screen or record the terminal standard error output, could use this flaw to gain sensitive information.Show less
1Claws Mail
1Vcalendar
Nov 21, 2024
Nov 25, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Claws Mail vCalendar plugin: credentials exposed on interface
5Buildah Project
Libpod ProjectOpensuse+2 more
6Buildah
Enterprise LinuxLeap+3 more
Jun 17, 2026
Nov 25, 2019
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container regi...Show more
The containers/image library used by the container tools Podman, Buildah, and Skopeo in Red Hat Enterprise Linux version 8 and CRI-O in OpenShift Container Platform, does not enforce TLS connections to the container registry authorization service. An attacker could use this vulnerability to launch a MiTM attack and steal login credentials or bearer tokens.Show less
3Debian
OpensuseRedhat
4Ansible
Backports SleDebian Linux+1 more
Jun 17, 2026
Nov 22, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters....Show more
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, prompt passwords by expanding them from templates as they could contain special characters. Passwords should be wrapped to prevent templates trigger and exposing them.Show less
1Loftek
1Nexus 543 Firmware
Nov 21, 2024
Nov 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from...Show more
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive information via an HTTP GET request to check_users.cgi. NOTE: cleartext passwords can also be obtained from proc/kcore when leveraging the directory traversal vulnerability in CVE-2013-3311.Show less
1Qmetry
1Jenkins Qmetry For Jira
Jun 17, 2026
Nov 21, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to...Show more
Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Spira Importer
Jun 17, 2026
Nov 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Anchore Container Image Scanner
Jun 17, 2026
Nov 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to...Show more
Jenkins Anchore Container Image Scanner Plugin 1.0.19 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Plex
1Media Server
Nov 21, 2024
Nov 18, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was as...Show more
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.Show less
1Mcafee
1Advanced Threat Defense
Jun 17, 2026
Nov 14, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was origin...Show more
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further detailsShow less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Nov 12, 2019
N/A· v4
9.9 CRITICAL· v3
6.5 MEDIUM· v2
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request...Show more
A security feature bypass vulnerability exists where a NETLOGON message is able to obtain the session key and sign messages.To exploit this vulnerability, an attacker could send a specially crafted authentication request, aka 'Microsoft Windows Security Feature Bypass Vulnerability'.Show less