← Back
CWE-522

1,466 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,466)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Serena Sra Deploy
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Crittercism Dsym
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Kmap
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Netsparker Cloud Scan
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Jabber Server
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Youtrack Plugin
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins youtrack-plugin Plugin 0.7.1 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
1Jenkins
1Deployhub
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins DeployHub Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Minio Storage
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Minio Storage Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Diawi Upload
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Mabl
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins mabl Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Klaros Testmanagement
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Klaros-Testmanagement Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Relution Enterprise Appstore Publisher
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Relution Enterprise Appstore Publisher Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Assembla Auth
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins Assembla Auth Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Starteam
Jun 17, 2026
Apr 4, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
Jenkins StarTeam Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Crowd Integration
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
1Jenkins
1Testfairy
Jun 17, 2026
Apr 4, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
1Trustsource
1Ecs Publisher
Jun 17, 2026
Mar 28, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this...Show more
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration.Show less
1Portainer
1Portainer
Nov 21, 2024
Mar 27, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.
1Redhat
1Ovirt Engine
Nov 21, 2024
Mar 25, 2019
N/A· v4
8.8 HIGH· v3
4.0 MEDIUM· v2
In ovirt-engine 4.1, if a host was provisioned with cloud-init, the root password could be revealed through the REST interface.
1Veritas
1Netbackup Appliance
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.2 HIGH· v3
4.0 MEDIUM· v2
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed to an administrator.