VYPR

CWE-256

Plaintext Storage of a Password

BaseIncompleteLikelihood: High

Description

The product stores a password in plaintext within resources such as memory or files.

Hierarchy (View 1000)

Parents

Children

none

CVEs mapped to this weakness (279)

page 6 of 14
  • CVE-2024-3623MedApr 25, 2024
    risk 0.42cvss 6.5epss 0.00

    A flaw was found when using mirror-registry to install Quay. It uses a default database secret key, which is stored in plain-text format in one of the configuration template files. This issue may lead to all instances of Quay deployed using mirror-registry to have the same…

  • CVE-2024-25138MedMar 26, 2024
    risk 0.42cvss 6.5epss 0.00

    In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.

  • CVE-2023-27315MedOct 12, 2023
    risk 0.42cvss 6.5epss 0.00

    SnapGathers versions prior to 4.9 are susceptible to a vulnerability which could allow a local authenticated attacker to discover plaintext domain user credentials

  • CVE-2023-35765MedJul 7, 2023
    risk 0.42cvss 6.5epss 0.01

    PiiGAB M-Bus stores credentials in a plaintext file, which could allow a low-level user to gain admin credentials.

  • CVE-2023-3395MedJul 3, 2023
    risk 0.42cvss 6.5epss 0.00

    ​All versions of the TWinSoft Configuration Tool store encrypted passwords as plaintext in memory. An attacker with access to system files could open a file to load the document into memory, including sensitive information associated with document, such as password. The…

  • CVE-2023-24450MedJan 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Jenkins view-cloner Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-45384MedNov 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Reverse Proxy Auth Plugin 1.7.3 and earlier stores the LDAP manager password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.

  • CVE-2022-41255MedSep 21, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins CONS3RT Plugin 1.0.0 and earlier stores Cons3rt API token unencrypted in job config.xml files on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-38665MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-33928MedAug 10, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Wyse Management Suite 3.6.1 and below contains an Plain-text Password Storage Vulnerability in UI. An attacker with low privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the…

  • CVE-2022-34816MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins HPE Network Virtualization Plugin 1.0 stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34809MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34807MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34806MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-34805MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34202MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34199MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-29085MedJun 2, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user…

  • CVE-2022-28135MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller…

  • CVE-2021-23207MedJan 21, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by…