VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,463)

page 63 of 74
  • CVE-2020-10710MedAug 16, 2022
    risk 0.29cvss 4.4epss 0.00

    A flaw was found where the Plaintext Candlepin password is disclosed while updating Red Hat Satellite through the satellite-installer. This flaw allows an attacker with sufficiently high privileges, such as root, to retrieve the Candlepin plaintext password.

  • CVE-2022-20621MedJan 12, 2022
    risk 0.29cvss 5.5epss 0.00

    Jenkins Metrics Plugin 4.0.2.8 and earlier stores an access key unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-20434MedSep 23, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Security Verify Bridge 1.0.5.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 196346.

  • CVE-2021-21681MedAug 31, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Nomad Plugin 0.7.4 and earlier stores Docker passwords unencrypted in the global config.xml file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2021-25284MedFeb 27, 2021
    risk 0.29cvss 4.4epss 0.01

    An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.

  • CVE-2020-4602MedJan 13, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Insights 2.0.2 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184836.

  • CVE-2021-21614MedJan 13, 2021
    risk 0.29cvss 5.5epss 0.00

    Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-4913MedJan 4, 2021
    risk 0.29cvss 4.4epss 0.00

    IBM Cloud Pak System 2.3 could reveal credential information in the HTTP response to a local privileged user. IBM X-Force ID: 191288.

  • CVE-2020-8152MedNov 16, 2020
    risk 0.29cvss 4.4epss 0.00

    Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the public key to decrypt them later on.

  • CVE-2019-4693MedAug 26, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Data Encryption (GDE) 3.0.0.2 stores user credentials in plain in clear text which can be read by a local privileged user. IBM X-Force ID: 171831.

  • CVE-2020-4593MedAug 24, 2020
    risk 0.29cvss 4.4epss 0.00

    IBM Security Guardium Insights 2.0.1 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 184747.

  • CVE-2020-6239MedJun 10, 2020
    risk 0.29cvss 4.4epss 0.00

    Under certain conditions SAP Business One (Backup service), versions 9.3, 10.0, allows an attacker with admin permissions to view SYSTEM user password in clear text, leading to Information Disclosure.

  • CVE-2020-5263MedApr 9, 2020
    risk 0.29cvss 5.5epss 0.01

    auth0.js (NPM package auth0-js) greater than version 8.0.0 and before version 9.12.3 has a vulnerability. In the case of an (authentication) error, the error object returned by the library contains the original request of the user, which may include the plaintext password the…

  • CVE-2014-4659MedFeb 20, 2020
    risk 0.29cvss 5.5epss 0.00

    Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "deb http://user:pass@server:port/" format.

  • CVE-2014-4660MedFeb 20, 2020
    risk 0.29cvss 5.5epss 0.00

    Ansible before 1.5.5 constructs filenames containing user and password fields on the basis of deb lines in sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by leveraging existence of a file that uses the "deb…

  • CVE-2019-10429MedSep 25, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins GitLab Logo Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-10398MedSep 12, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10361MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.

  • CVE-2019-10345MedJul 31, 2019
    risk 0.29cvss 5.5epss 0.00

    Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.

  • CVE-2019-11092MedJun 13, 2019
    risk 0.29cvss 4.4epss 0.00

    Insufficient password protection in the attestation database for Open CIT may allow an authenticated user to potentially enable information disclosure via local access.