Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2019-10420

Published Sep 25, 2019

Jenkins Assembla Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file syst…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10419

Published Sep 25, 2019

Jenkins vFabric Application Director Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10416

Published Sep 25, 2019

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10415

Published Sep 25, 2019

Jenkins Violation Comments to GitLab Plugin 2.28 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by us…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10414

Published Sep 25, 2019

Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read p…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10413

Published Sep 25, 2019

Jenkins Data Theorem: CI/CD Plugin 1.3 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended R…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15635

Published Sep 23, 2019

An issue was discovered in Grafana 5.4.0. Passwords for data sources used by Grafana (e.g., MySQL) are not encrypted. An admin user can reveal passwords for any data source by pre…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11664

Published Sep 18, 2019

Clear text password in browser in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52, 9.60, 9.61, 9.62. The vulnerabilit…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11663

Published Sep 18, 2019

Clear text credentials are used to access managers app in Tomcat in Micro Focus Service Manager product versions 9.30, 9.31, 9.32, 9.33, 9.34, 9.35, 9.40, 9.41, 9.50, 9.51, 9.52,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5534

Published Sep 18, 2019

VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disclosure vulnerability where Virtual Machines deployed from a…

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2018-7820

Published Sep 17, 2019

A Credentials Management CWE-255 vulnerability exists in the APC UPS Network Management Card 2 AOS v6.5.6, which could cause Remote Monitoring Credentials to be viewed in plaintex…

CVSS 9.8 · Critical

CVE-2019-10398

Published Sep 12, 2019

Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11769

Published Sep 11, 2019

An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering administrative credentials into the GUI. Subsequently, these c…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13349

Published Sep 5, 2019

In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-13348

Published Aug 28, 2019

In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13421

Published Aug 23, 2019

Search Guard versions before 23.1 had an issue that an administrative user is able to retrieve bcrypt password hashes of other users configured in the internal user database.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10960

Published Aug 20, 2019

Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functiona…

CVSS 7.5 · High

CVE-2019-15052

Published Aug 14, 2019

The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host. If that host returns a 30x redirect, Gradle also sends those cre…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10385

Published Aug 7, 2019

Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permissio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10379

Published Aug 7, 2019

Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed b…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10378

Published Aug 7, 2019

Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,076-1,100 of 1,395 CVEsPage 44 of 56