← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Jira Ext
Jun 17, 2026
Apr 18, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1F5
14Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+11 more
Jun 17, 2026
Apr 15, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0....Show more
Platform dependent weakness. This issue only impacts iSeries platforms. On these platforms, in BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, Edge Gateway, FPS, GTM, Link Controller, PEM, WebAccelerator) versions 14.0.0-14.1.0.1, 13.0.0-13.1.1.3, and 12.1.1 HF2-12.1.4, the secureKeyCapable attribute was not set which causes secure vault to not use the F5 hardware support to store the unit key. Instead the unit key is stored in plaintext on disk as would be the case for Z100 systems. Additionally this causes the unit key to be stored in UCS files taken on these platforms.Show less
1Aveva
1Wonderware System Platform
Jun 17, 2026
Apr 11, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to...Show more
AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with low privileges could make use of an API to obtain the credentials for this account.Show less
1Juniper
1Junos
Jun 17, 2026
Apr 10, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems boot...Show more
When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentication plain-text-password" on systems booted from an OAM (Operations, Administration, and Maintenance) volume, leading to a possible administrative bypass with physical access to the console. OAM volumes (e.g. flash drives) are typically instantiated as /dev/gpt/oam, or /oam for short. Password recovery, changing the root password from a console, should not have been allowed from an insecure console. Affected releases are Juniper Networks Junos OS: 15.1 versions prior to 15.1F6-S12, 15.1R7-S3; 15.1X49 versions prior to 15.1X49-D160; 15.1X53 versions prior to 15.1X53-D236, 15.1X53-D496, 15.1X53-D68; 16.1 versions prior to 16.1R3-S10, 16.1R6-S6, 16.1R7-S3; 16.1X65 versions prior to 16.1X65-D49; 16.2 versions prior to 16.2R2-S8; 17.1 versions prior to 17.1R2-S10, 17.1R3; 17.2 versions prior to 17.2R1-S8, 17.2R3-S1; 17.3 versions prior to 17.3R3-S3; 17.4 versions prior to 17.4R1-S6, 17.4R2-S2; 18.1 versions prior to 18.1R2-S4, 18.1R3-S3; 18.2 versions prior to 18.2R2; 18.2X75 versions prior to 18.2X75-D40; 18.3 versions prior to 18.3R1-S2. This issue does not affect Junos OS releases prior to 15.1.Show less
1Juniper
2Service Insight
Service Now
Jun 17, 2026
Apr 10, 2019
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credenti...Show more
A password management issue exists where the Organization authentication username and password were stored in plaintext in log files. A locally authenticated attacker who is able to access these stored plaintext credentials can use them to login to the Organization. Affected products are: Juniper Networks Service Insight versions from 15.1R1, prior to 18.1R1. Service Now versions from 15.1R1, prior to 18.1R1.Show less
1Rapid7
1Insightvm
Jun 17, 2026
Apr 9, 2019
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those passw...Show more
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring backups, as well as the salt for those passwords. Valid credentials are required to access these files and malicious users would still need to perform additional work to decrypt the credentials and escalate privileges. This issue affects: Rapid7 InsightVM versions 6.5.11 through 6.5.49.Show less
1Zyxel
1Nas326 Firmware
Jun 17, 2026
Apr 9, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
A plaintext password vulnerability in the Zyxel NAS 326 through 5.21 allows an elevated privileged user to get the admin password of the device.
1Jenkins
1Cloudcoreo Deploytime
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Koji
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Sametime
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Serena Sra Deploy
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Crittercism Dsym
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Kmap
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Netsparker Cloud Scan
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Jabber Server
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Youtrack Plugin
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Deployhub
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Minio Storage
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Diawi Upload
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Mabl
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.