VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 55 of 74
  • CVE-2025-54380MedJul 26, 2025
    risk 0.35cvss 6.5epss 0.00

    Opencast is a free, open-source platform to support the management of educational audio and video content. Prior to version 17.6, Opencast would incorrectly send the hashed global system account credentials (ie: org.opencastproject.security.digest.user and…

  • CVE-2024-47529MedOct 2, 2024
    risk 0.35cvss 6.5epss 0.00

    OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of a web browser. This makes the user password susceptible to exfiltration via…

  • CVE-2024-7813MedAug 15, 2024
    risk 0.35cvss 5.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in SourceCodester Prison Management System 1.0. This issue affects some unknown processing of the file /uploadImage/Profile/ of the component Profile Image Handler. The manipulation leads to insufficiently…

  • CVE-2023-46651MedOct 25, 2023
    risk 0.35cvss 6.5epss 0.01

    Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backported to 10.4.1.

  • CVE-2022-43419MedOct 19, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Katalon Plugin 1.0.32 and earlier stores API keys unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.

  • CVE-2022-38663MedAug 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.

  • CVE-2022-36901MedJul 27, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins HTTP Request Plugin 1.15 and earlier stores HTTP Request passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2022-1413MedMay 19, 2022
    risk 0.35cvss 5.4epss 0.01

    Missing input masking in GitLab CE/EE affecting all versions starting from 1.0.2 before 14.8.6, all versions from 14.9.0 before 14.9.4, and all versions from 14.10.0 before 14.10.1 causes potentially sensitive integration properties to be disclosed in the web interface

  • CVE-2022-30952MedMay 17, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Pipeline SCM API for Blue Ocean Plugin 1.25.3 and earlier allows attackers with Job/Configure permission to access credentials with attacker-specified IDs stored in the private per-user credentials stores of any attacker-specified user in Jenkins.

  • CVE-2022-25187MedFeb 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Support Core Plugin 2.79 and earlier does not redact some sensitive information in the support bundle.

  • CVE-2022-25184MedFeb 15, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins Pipeline: Build Step Plugin 2.15 and earlier reveals password parameter default values when generating a pipeline script using the Pipeline Snippet Generator, allowing attackers with Item/Read permission to retrieve the default password parameter value from jobs.

  • CVE-2022-23109MedJan 12, 2022
    risk 0.35cvss 6.5epss 0.01

    Jenkins HashiCorp Vault Plugin 3.7.0 and earlier does not mask Vault credentials in Pipeline build logs or in Pipeline step descriptions when Pipeline: Groovy Plugin 2.85 or later is installed.

  • CVE-2021-39342MedSep 29, 2021
    risk 0.35cvss 5.3epss 0.01

    The Credova_Financial WordPress plugin discloses a site's associated Credova API account username and password in plaintext via an AJAX action whenever a site user goes to checkout on a page that has the Credova Financing option enabled. This affects versions up to, and…

  • CVE-2021-38165MedAug 7, 2021
    risk 0.35cvss 5.3epss 0.04

    Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.

  • CVE-2021-22923MedAug 5, 2021
    risk 0.35cvss 5.3epss 0.02

    When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents…

  • CVE-2020-27839MedMay 26, 2021
    risk 0.35cvss 5.4epss 0.02

    A flaw was found in ceph-dashboard. The JSON Web Token (JWT) used for user authentication is stored by the frontend application in the browser’s localStorage which is potentially vulnerable to attackers via XSS attacks. The highest threat from this vulnerability is to data…

  • CVE-2021-30169MedApr 28, 2021
    risk 0.35cvss 5.3epss 0.02

    The sensitive information of webcam device is not properly protected. Remote attackers can unauthentically grant user’s credential.

  • CVE-2021-21634MedMar 30, 2021
    risk 0.35cvss 6.5epss 0.01

    Jenkins Jabber (XMPP) notifier and control Plugin 1.41 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-20410MedFeb 12, 2021
    risk 0.35cvss 5.3epss 0.01

    IBM Security Verify Information Queue 1.0.6 and 1.0.7 sends user credentials in plain clear text which can be read by an authenticated user using man in the middle techniques. IBM X-Force ID: 198190.

  • CVE-2020-10755MedJun 10, 2020
    risk 0.35cvss 6.5epss 0.01

    An insecure-credentials flaw was found in all openstack-cinder versions before openstack-cinder 14.1.0, all openstack-cinder 15.x.x versions before openstack-cinder 15.2.0 and all openstack-cinder 16.x.x versions before openstack-cinder 16.1.0. When using openstack-cinder with…