Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2019-10366

Published Jul 31, 2019

Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10361

Published Jul 31, 2019

Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-1010241

Published Jul 19, 2019

Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format. The impact is: Authenticated users can recover credentials. The…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-8932

Published Jul 17, 2019

Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-1010308

Published Jul 15, 2019

Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control. The impact is: The access to the log file is not restricted. It contains sensitive inf…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10347

Published Jul 11, 2019

Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-12171

Published Jul 8, 2019

Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9873

Published Jul 3, 2019

In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9872

Published Jul 3, 2019

In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server cre…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-9823

Published Jul 3, 2019

In several JetBrains IntelliJ IDEA versions, creating remote run configurations of JavaEE application servers leads to saving a cleartext record of the server credentials in the I…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-12847

Published Jul 3, 2019

In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the admin user. It is only relevant in cases where a password h…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13179

Published Jul 2, 2019

Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root) to /boot within a globally readable initramfs image with…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-13054

Published Jun 29, 2019

The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection. On Windows, any text may be injected by using ALT+NUMPAD input to…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-4385

Published Jun 19, 2019

IBM Spectrum Protect Plus 10.1.2 may display the vSnap CIFS password in the IBM Spectrum Protect Plus Joblog. This can result in an attacker gaining access to sensitive informatio…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11271

Published Jun 19, 2019

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-4239

Published Jun 14, 2019

IBM MQ Advanced Cloud Pak (IBM Cloud Private 1.0.0 through 3.0.1) stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 159465.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1,101-1,125 of 1,395 CVEsPage 45 of 56