CWE-522

Insufficiently Protected Credentials

Parent: CWE-1390 - Weak Authentication

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

1,363 vulnerabilities with CWE-522
CVE-2019-10295 HIGH
Jenkins crittercism-dsym Plugin - Insufficiently Protected Credentials in config.xml
CVSS 8.8
CVE-2019-10294 HIGH
Jenkins Kmap Plugin - Insufficiently Protected Credentials in Job config.xml
CVSS 8.8
CVE-2019-10291 HIGH
Jenkins Netsparker Cloud Scan Plugin < 1.1.5 - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-10288 HIGH
Jenkins Jabber Server Plugin - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-10287 HIGH
Jenkins youtrack-plugin < 0.7.1 - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-10286 HIGH
Jenkins DeployHub Plugin < 8.0.14 - Insufficiently Protected Credentials in config.xml
CVSS 8.8
CVE-2019-10285 HIGH
Jenkins Minio Storage Plugin - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-10284 HIGH
Jenkins Diawi Upload Plugin - Insufficiently Protected Credentials in Job Configuration
CVSS 8.8
CVE-2019-10283 HIGH
Jenkins mabl Plugin < 0.0.13 - Insufficiently Protected Credentials in Job Config
CVSS 8.8
CVE-2019-10282 HIGH
Jenkins Klaros-Testmanagement Plugin < 2.1.0 - Insufficiently Protected Credentials in Job Config Files
CVSS 8.8
CVE-2019-10281 HIGH
Jenkins Relution Enterprise Appstore Publisher Plugin - Insufficiently Protected Credentials
CVSS 8.8
CVE-2019-10280 HIGH
Jenkins Assembla Auth Plugin < 1.13 - Insufficiently Protected Credentials in config.xml
CVSS 8.8
CVE-2019-10277 HIGH
Jenkins StarTeam Plugin - Insufficiently Protected Credentials in Job Configuration
CVSS 8.8
CVE-2019-1003097 MEDIUM
Jenkins Crowd Integration Plugin - Info Disclosure
CVSS 6.5
CVE-2019-1003096 MEDIUM
Jenkins TestFairy Plugin - Info Disclosure
CVSS 6.5
CVE-2019-1003045 MEDIUM
Jenkins ECS Publisher Plugin <1.0.0 - Info Disclosure
CVSS 6.5
CVE-2019-9868 HIGH
Veritas NetBackup Appliance <3.1.2 - Info Disclosure
CVSS 7.2
CVE-2019-9867 HIGH
Veritas NetBackup Appliance <3.1.2 - Info Disclosure
CVSS 7.2
CVE-2019-5723 CRITICAL
portier 4.4.4.2 and 4.4.4.6 - Insufficiently Protected Credentials via Reversible Encryption
CVSS 9.8
CVE-2019-1003039 HIGH
JenkinsAppDynamics Dashboard Plugin <1.0.14 - Info Disclosure
CVSS 8.8
CVE-2019-1003038 HIGH
Jenkins Repository Connector Plugin <1.2.4 - Info Disclosure
CVSS 7.8
CVE-2019-3780 HIGH
Cloud Foundry Container Runtime < 0.28.0 - Unprotected IAAS Credential Exposure in K8s Worker Node Configuration
CVSS 8.8
CVE-2019-4059 CRITICAL
IBM Rational ClearCase 9.0.1-9.0.1.5 - Insufficiently Protected Credentials
CVSS 9.8
CVE-2019-3782 HIGH
Cloud Foundry CredHub CLI < 2.2.1 - Insufficiently Protected Credentials via Environment Variable Exposure
CVSS 7.8
CVE-2019-6549 HIGH
PR100088 Modbus Gateway Firmware < r02 - Unauthenticated Plain-Text Credential Exposure via FTP
CVSS 7.2
Details
Vulnerabilities 1,363