CWE-522
1,396 CVEs • Abstraction: Class
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
CVEs (1,396)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system...Show more |
1Jenkins 1Elasticsearch Query Jun 17, 2026 Jun 30, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file syste...Show more |
Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller...Show more |
Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system. |
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (...Show more |
1Jenkins 1Rocketchat Notifier Jun 17, 2026 Jun 30, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the...Show more |
1Jenkins 1Build Notifications Jun 17, 2026 Jun 30, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file syst...Show more |
1Jenkins 1Deployment Dashboard Jun 17, 2026 Jun 30, 2022 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file s...Show more |
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation b...Show more |
2Debian Ldap Account Manager2Debian Linux Ldap Account ManagerJun 17, 2026 Jun 27, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clea...Show more |
1Devolutions 1Remote Desktop Manager Jun 17, 2026 Jun 27, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desk...Show more |
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log |
1Ibm 3Robotic Process Automation Robotic Process Automation As A ServiceRobotic Process Automation For Cloud PakJun 17, 2026 Jun 24, 2022 N/A· v4 4.6 MEDIUM· v3 2.1 LOW· v2 IBM Robotic Process Automation 21.0.1 and 21.0.2 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected access tokens. IBM X-Force ID: 229198. |
1Secheron 1Sepcos Control And Protection Relay Firmware Jun 17, 2026 Jun 24, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An attacker with weak credentials could access the TCP port via an open FTP port, allowing an attacker to read sensitive files and write to remotely executable directories. |
1Secheron 1Sepcos Control And Protection Relay Firmware Jun 17, 2026 Jun 24, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool. |
1Jenkins 1Squash Tm Publisher Jun 17, 2026 Jun 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins c...Show more |
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system. |
1Jenkins 1Convertigo Mobile Platform Jun 17, 2026 Jun 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the J...Show more |
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An atta...Show more |
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save. |