CWE-522
1,466 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,466)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes. |
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases. |
Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database. |
1Zebra 8220xi4 Firmware Zt220 FirmwareZt230 Firmware+5 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, speci...Show more |
1Dell 6Emc Powerconnect 7000 Firmware Emc Powerconnect 8024 FirmwareEmc Powerconnect M6220 Firmware+3 moreJun 17, 2026 Aug 20, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability. TACACS\Radius credentials are stored in plain text in the...Show more |
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those credentials to all subsequent hosts that the...Show more |
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. |
1Google 1Cloud Messaging Notification Jun 17, 2026 Aug 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sy...Show more |
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system. |
1Microdigital 3Mdc N2190v Firmware Mdc N4090 FirmwareMdc N4090w FirmwareJun 17, 2026 Aug 6, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5. The file in question is /usr/local/ipsca/mipsca.db. If a camera is compromised, the attacker can gain a...Show more |
27Anynines ApigeeAppdynamics+24 more55Application Analytics Application MonitoringApplication Performance Monitoring+52 moreJun 17, 2026 Aug 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with acces...Show more |
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file...Show more |
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system. |
1Jenkins 1Configuration As Code Jun 17, 2026 Jul 31, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export. |
Fleet before 2.1.2 allows exposure of SMTP credentials. |
1Jenkins 1Credentials Binding Jun 17, 2026 Jul 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The component is: config-variables.jelly lin...Show more |
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application. |
1Aquaverde 1Aquarius Cms Jun 17, 2026 Jul 15, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive information like passwords etc. The componen...Show more |
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs because of incorrect protection of VPN certificates (used for initiating a VPN session to the Alarm.co...Show more |
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system. |