Skip to main content

CWE archive

CWE-522 CVEs

Programmatic archive

1,395 CVEs tagged with CWE-522217 Critical, 485 High, 646 Medium, 45 Low, 2 Unrated.

CVE-2019-11885

Published May 12, 2019

eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB traffic or by sending a 06 05 52 41 01 b0 00 00 00 00 00 00 S…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11820

Published May 9, 2019

Information exposure through process environment vulnerability in Synology Calendar before 2.3.3-0620 allows local users to obtain credentials via cmdline.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10318

Published Apr 30, 2019

Jenkins Azure AD Plugin 0.3.3 and earlier stored the client secret unencrypted in the global config.xml configuration file on the Jenkins master where it could be viewed by users…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10316

Published Apr 30, 2019

Jenkins Aqua MicroScanner Plugin 1.0.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10313

Published Apr 30, 2019

Jenkins Twitter Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file syste…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10239

Published Apr 24, 2019

Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (under the same user context) to obtain cleartext credentials…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-11402

Published Apr 22, 2019

In Gradle Enterprise before 2018.5.3, Build Cache Nodes did not store the credentials at rest in an encrypted format.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-11350

Published Apr 19, 2019

CloudBees Jenkins Operations Center 2.150.2.3, when an expired trial license exists, allows Cleartext Password Storage and Retrieval via the proxy configuration page.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-10302

Published Apr 18, 2019

Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to th…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-6525

Published Apr 11, 2019

AVEVA Wonderware System Platform 2017 Update 2 and prior uses an ArchestrA network user account for authentication of system processes and inter-node communications. A user with l…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-0035

Published Apr 10, 2019

When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the root password can be changed using "set system root-authentica…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-5615

Published Apr 9, 2019

Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Global Administrators and clear-text passwords for restoring bac…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10299

Published Apr 4, 2019

Jenkins CloudCoreo DeployTime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the mas…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10298

Published Apr 4, 2019

Jenkins Koji Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10297

Published Apr 4, 2019

Jenkins Sametime Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file syst…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10296

Published Apr 4, 2019

Jenkins Serena SRA Deploy Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10295

Published Apr 4, 2019

Jenkins crittercism-dsym Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or ac…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10294

Published Apr 4, 2019

Jenkins Kmap Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10291

Published Apr 4, 2019

Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10288

Published Apr 4, 2019

Jenkins Jabber Server Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1,151-1,175 of 1,395 CVEsPage 47 of 56