VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 41 of 74
  • CVE-2022-28167MedJun 27, 2022
    risk 0.42cvss 6.5epss 0.01

    Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log

  • CVE-2022-1666MedJun 24, 2022
    risk 0.42cvss 6.5epss 0.01

    The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.

  • CVE-2022-34213MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34202MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-34199MedJun 23, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2020-28865HigJun 16, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.

  • CVE-2022-29085MedJun 2, 2022
    risk 0.42cvss 6.4epss 0.00

    Dell Unity, Dell UnityVSA, and Dell Unity XT versions prior to 5.2.0.0.5.173 contain a plain-text password storage vulnerability when certain off-array tools are run on the system. The credentials of a user with high privileges are stored in plain text. A local malicious user…

  • CVE-2022-28141MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-28135MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins instant-messaging Plugin 1.41 and earlier stores passwords for group chats unencrypted in the global configuration file of plugins based on Jenkins instant-messaging Plugin on the Jenkins controller where they can be viewed by users with access to the Jenkins controller…

  • CVE-2022-0859MedMar 23, 2022
    risk 0.42cvss 6.5epss 0.00

    McAfee Enterprise ePolicy Orchestrator (ePO) prior to 5.10 Update 13 allows a local attacker to point an ePO server to an arbitrary SQL server during the restoration of the ePO server. To achieve this the attacker would have to be logged onto the server hosting the ePO server…

  • CVE-2022-27217MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Vmware vRealize CodeStream Plugin 1.2 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-27216MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins dbCharts Plugin 0.5.2 and earlier stores JDBC connection passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-27206MedMar 15, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins GitLab Authentication Plugin 1.13 and earlier stores the GitLab client secret unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-24982MedFeb 16, 2022
    risk 0.42cvss 6.5epss 0.01

    Forms generated by JQueryForm.com before 2022-02-05 allows a remote authenticated attacker to access the cleartext credentials of all other form users. admin.php contains a hidden base64-encoded string with these credentials.

  • CVE-2022-23223HigJan 25, 2022
    risk 0.42cvss 7.5epss 0.04

    On Apache ShenYu versions 2.4.0 and 2.4.1, and endpoint existed that disclosed the passwords of all users. Users are recommended to upgrade to version 2.4.2 or later.

  • CVE-2021-23207MedJan 21, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker with physical access to the host can extract the secrets from the registry and create valid JWT tokens for the Fresenius Kabi Vigilant MasterMed version 2.0.1.3 application and impersonate arbitrary users. An attacker could manipulate RabbitMQ queues and messages by…

  • CVE-2021-42023MedDec 14, 2021
    risk 0.42cvss 6.5epss 0.01

    A vulnerability has been identified in ModelSim Simulation (All versions), Questa Simulation (All versions). The RSA white-box implementation in affected applications insufficiently protects the built-in private keys that are required to decrypt electronic intellectual property…

  • CVE-2021-37187MedDec 10, 2021
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered on Digi TransPort devices through 2021-07-21. An authenticated attacker may read a password file (with reversible passwords) from the device, which allows decoding of other users' passwords.

  • CVE-2021-43332MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    In GNU Mailman before 2.1.36, the CSRF token for the Cgi/admindb.py admindb page contains an encrypted version of the list admin password. This could potentially be cracked by a moderator via an offline brute-force attack.

  • CVE-2021-41972MedNov 12, 2021
    risk 0.42cvss 6.5epss 0.01

    Apache Superset up to and including 1.3.1 allowed for database connections password leak for authenticated users. This information could be accessed in a non-trivial way.