The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
1,360 vulnerabilities with CWE-522
CVE-2019-16543
MEDIUM
Jenkins Spira Importer Plugin <3.2.2 - Info Disclosure
CVSS 5.5
CVE-2019-16542
MEDIUM
Jenkins Anchore Container Image Scanner Plugin <1.0.19 - Info Discl...
CVSS 6.5
CVE-2019-3663
CRITICAL
McAfee Advanced Threat Defense < 4.8 - Unprotected Storage of Credentials
CVSS 9.8
CVE-2019-1384
CRITICAL
Microsoft Windows - Privilege Escalation
CVSS 9.9
CVE-2019-10210
HIGH
Postgresql <11.5-9.4.24 - Info Disclosure
CVSS 7.0
CVE-2019-4307
MEDIUM
IBM Security Guardium Big Data Intelligence - Info Disclosure
CVSS 5.5
CVE-2019-14929
CRITICAL
Mitsubishi Electric and INEA ME-RTU Firmware < 2.02 and < 3.0 - Unauthenticated Cleartext Password Exposure
CVSS 9.8
CVE-2019-10476
HIGH
Jenkins Zulip Plugin < 1.1.0 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2019-10467
MEDIUM
Jenkins Sonar Gerrit Plugin < 2.3 - Insufficiently Protected Credentials in Job Config
CVSS 6.5
CVE-2019-10461
HIGH
Jenkins Dynatrace Application Monitoring < 2.1.3 - Insufficiently Protected Credentials
CVSS 7.8
CVE-2019-10460
HIGH
Jenkins Bitbucket OAuth Plugin < 0.9 - Unprotected Credential Storage in config.xml
CVSS 7.8
CVE-2019-10459
MEDIUM
Jenkins Mattermost Notification Plugin < 2.7.0 - Insufficiently Protected Credentials in Global Configuration
CVSS 6.5
CVE-2019-17393
CRITICAL
Tomedo Server 1.7.3 - Cleartext Transmission of Sensitive Information via HTTP
CVSS 9.8
CVE-2019-11284
HIGH
Reactor Netty < 0.8.11 - Unauthenticated Credential Exposure via Redirect Header Handling
CVSS 8.6
CVE-2019-17662
CRITICAL
ThinVNC 1.0b1 - Path Traversal and Arbitrary File Read via ThinVnc.ini
CVSS 9.8
CVE-2019-10448
HIGH
Jenkins Extensive Testing Plugin - Insufficiently Protected Credentials in Job Config Files
CVSS 8.8
CVE-2019-17356
MEDIUM
Infinite Design 3.4.12 - Cleartext Transmission of Sensitive Information via TCP
CVSS 6.5
CVE-2019-17497
MEDIUM
PDF-XChange Editor < 8.0.330.0 - NTLM SSO Hash Theft via Crafted FDF/XFDF Files
CVSS 6.5
CVE-2019-9533
CRITICAL
Cobham EXPLORER 710 - Info Disclosure
CVSS 9.8
CVE-2019-0072
MEDIUM
Juniper Networks SBR <8.4.1R13, <8.5.0R4 - Info Disclosure
CVSS 5.6
CVE-2019-10429
MEDIUM
Jenkins GitLab Logo Plugin < 1.0.3 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-10426
MEDIUM
Jenkins Gem Publisher Plugin < 1.0 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-10425
MEDIUM
Jenkins Google Calendar Plugin < 0.4 - Insufficiently Protected Credentials
CVSS 6.5
CVE-2019-10424
MEDIUM
Jenkins elOyente Plugin < 1.3 - Insufficiently Protected Credentials
CVSS 5.5
CVE-2019-10423
MEDIUM
Jenkins CodeScan Plugin < 0.11 - Insufficiently Protected Credentials
CVSS 5.5
Details
Vulnerabilities
1,360