← Back
CWE-522

1,466 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Knowage Suite
1Knowage
Jun 17, 2026
Sep 5, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
1Eng
1Knowage
Jun 17, 2026
Aug 28, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
1Search Guard
1Search Guard
Jun 17, 2026
Aug 23, 2019
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.
1Zebra
8220xi4 Firmware
Zt220 FirmwareZt230 Firmware+5 more
Jun 17, 2026
Aug 20, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, speci...Show more
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.Show less
1Dell
6Emc Powerconnect 7000 Firmware
Emc Powerconnect 8024 FirmwareEmc Powerconnect M6220 Firmware+3 more
Jun 17, 2026
Aug 20, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the...Show more
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the system settings menu. An authenticated malicious user with access to the system settings menu may obtain the exposed password to use it in further attacks.Show less
1Gradle
1Gradle
Jun 17, 2026
Aug 14, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the...Show more
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the request redirects to. This is similar to CVE-2018-1000007.Show less
1Jenkins
1Eggplant
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Google
1Cloud Messaging Notification
Jun 17, 2026
Aug 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy...Show more
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.Show less
1Jenkins
1Testlink
Jun 17, 2026
Aug 7, 2019
N/A· v4
5.3 MEDIUM· v3
2.1 LOW· v2
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Microdigital
3Mdc N2190v Firmware
Mdc N4090 FirmwareMdc N4090w Firmware
Jun 17, 2026
Aug 6, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain a...Show more
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain access to passwords and abuse them to compromise further systems.Show less
27Anynines
ApigeeAppdynamics+24 more
55Application Analytics
Application MonitoringApplication Performance Monitoring+52 more
Jun 17, 2026
Aug 5, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.Show less
1Jenkins
1Skytap Cloud Ci
Jun 17, 2026
Jul 31, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file...Show more
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1M2release
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Configuration As Code
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
1Kolide
1Fleet
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fleet before 2.1.2 allows exposure of SMTP credentials.
1Jenkins
1Credentials Binding
Jun 17, 2026
Jul 19, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly lin...Show more
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly line #30 (passwordVariable). The attack vector is: Attacker creates and executes a Jenkins job.Show less
1Rdbrck
1Shift
Jun 17, 2026
Jul 17, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
1Aquaverde
1Aquarius Cms
Jun 17, 2026
Jul 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The componen...Show more
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The component is: log file. The attack vector is: open the file.Show less
1Alarm
1Adc V522ir Firmware
Jun 17, 2026
Jul 11, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.co...Show more
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.com infrastructure) on the local camera device.Show less
1Jenkins
1Mashup Portlets
Jun 17, 2026
Jul 11, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.