Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,427 CVEs tagged with CWE-522223 Critical, 496 High, 656 Medium, 50 Low, 2 Unrated.

CVE-2020-5404

Published Mar 3, 2020

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentials leak during a redirect to a…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4659

Published Feb 20, 2020

Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-4660

Published Feb 20, 2020

Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credenti…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2133

Published Feb 12, 2020

Jenkins Applatix Plugin 1.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2132

Published Feb 12, 2020

Jenkins Parasoft Environment Manager Plugin 2.14 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Exten…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2131

Published Feb 12, 2020

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permis…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2130

Published Feb 12, 2020

Jenkins Harvest SCM Plugin 0.5.1 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to th…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2129

Published Feb 12, 2020

Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to t…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2128

Published Feb 12, 2020

Jenkins ECX Copy Data Management Plugin 1.9 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended R…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2127

Published Feb 12, 2020

Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2126

Published Feb 12, 2020

Jenkins DigitalOcean Plugin 1.1 and earlier stores a token unencrypted in the global config.xml file on the Jenkins master where it can be viewed by users with access to the maste…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2125

Published Feb 12, 2020

Jenkins Debian Package Builder Plugin 1.6.11 and earlier stores a GPG passphrase unencrypted in its global configuration file on the Jenkins master where it can be viewed by users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2124

Published Feb 12, 2020

Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier stores a password unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2119

Published Feb 12, 2020

Jenkins Azure AD Plugin 1.1.2 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their exposure.

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2114

Published Feb 12, 2020

Jenkins S3 publisher Plugin 0.11.4 and earlier transmits configured credentials in plain text as part of the global Jenkins configuration form, potentially resulting in their expo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1,001-1,025 of 1,427 CVEsPage 41 of 58