← Back
CWE-522

1,396 CVEs • Abstraction: Class

Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

JSON object

Loading...

CVEs (1,396)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Redhat
1Ansible
Nov 21, 2024
Feb 20, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumsta...Show more
Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb http://user:pass@server:port/" format.Show less
1Jenkins
1Applatix
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
1Jenkins
1Parasoft Environment Manager
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the mas...Show more
Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Harvest Scm
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system...Show more
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Harvest Scm
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Eagle Tester
Jun 17, 2026
Feb 12, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Ecx Copy Data Management
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master f...Show more
Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Bmc Release Package And Deployment
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file sys...Show more
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.Show less
1Jenkins
1Digitalocean
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Debian Package Builder
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.
1Jenkins
1Dynamic Extended Choice Parameter
Jun 17, 2026
Feb 12, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to t...Show more
Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.Show less
1Jenkins
1Azure Ad
Jun 17, 2026
Feb 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
1Jenkins
1S3 Publisher
Jun 17, 2026
Feb 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.
1Automationdirect
11C More Ea9 Rhi Firmware
C More Ea9 T10cl FirmwareC More Ea9 T10wcl Firmware+8 more
Jun 17, 2026
Feb 5, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and...Show more
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.Show less
1Dlink
1Dir 100 Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
D-Link DIR-100 4.03B07 has PPTP and poe information disclosure
1Dlink
1Dir 100 Firmware
Nov 21, 2024
Feb 4, 2020
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
1Brother
1Mfc 9970cdw Firmware
Nov 21, 2024
Feb 3, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Brother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
1Paessler
1Prtg Network Monitor
Jun 17, 2026
Feb 3, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative...Show more
An issue was discovered in PRTG 7.x through 19.4.53. Due to insufficient access control on local registry keys for the Core Server Service, a non-administrative user on the local machine is able to access administrative credentials.Show less
1Logmein
1Lastpass
Nov 21, 2024
Jan 31, 2020
N/A· v4
6.8 MEDIUM· v3
1.9 LOW· v2
LastPass prior to 2.5.1 has an insecure PIN implementation.
1Jetbrains
1Teamcity
Jun 17, 2026
Jan 30, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In JetBrains TeamCity before 2019.1.5, some server-stored passwords could be shown via the web UI.