VYPR

CWE-522

Insufficiently Protected Credentials

ClassIncomplete

Description

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-102 · CAPEC-474 · CAPEC-50 · CAPEC-509 · CAPEC-551 · CAPEC-555 · CAPEC-560 · CAPEC-561 · CAPEC-600 · CAPEC-644 · CAPEC-645 · CAPEC-652 · CAPEC-653

CVEs mapped to this weakness (1,534)

page 70 of 77
  • CVE-2020-2107MedJan 29, 2020
    risk 0.28cvss 4.3epss 0.01

    Jenkins Fortify Plugin 19.1.29 and earlier stores proxy server passwords unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2019-10421MedSep 25, 2019
    risk 0.28cvss 4.3epss 0.01

    Jenkins Azure Event Grid Build Notifier Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.

  • CVE-2018-15456MedJan 10, 2019
    risk 0.28cvss 4.3epss 0.01

    A vulnerability in the Admin Portal of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view saved passwords in plain text. The vulnerability is due to the incorrect inclusion of saved passwords when loading configuration pages in the Admin…

  • CVE-2017-5189MedMar 2, 2018
    risk 0.28cvss 4.3epss 0.01

    NetIQ iManager before 3.0.3 delivered a SSL private key in a Java application (JAR file) for authentication to Sentinel, allowing attackers to extract and establish their own connections to the Sentinel appliance.

  • CVE-2026-67339MedAug 1, 2026
    risk 0.27cvss 5.3epss 0.00

    guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can capture proxy credentials through origin server access logs when requests are redirected, bypassed, or sent through SOCKS proxies…

  • CVE-2026-49949MedJun 11, 2026
    risk 0.27cvss 5.3epss 0.00

    CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed…

  • CVE-2024-45636MedJun 11, 2026
    risk 0.27cvss 4.1epss 0.00

    IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.

  • CVE-2026-41345MedApr 23, 2026
    risk 0.27cvss 5.3epss 0.00

    OpenClaw before 2026.3.31 contains a credential exposure vulnerability in media download functionality that forwards Authorization headers across cross-origin redirects. Attackers can exploit this by crafting malicious cross-origin redirect chains to intercept sensitive…

  • CVE-2026-22574MedApr 14, 2026
    risk 0.27cvss 4.1epss 0.00

    A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0…

  • CVE-2025-54467MedSep 17, 2025
    risk 0.27cvss 5.3epss 0.00

    When a Java command with password parameters is executed and terminated by NeuVector for Process rule violation the password will appear in the NeuVector security event log.

  • CVE-2024-47162MedSep 19, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains YouTrack before 2024.3.44799 token could be revealed on Imports page

  • CVE-2024-39278MedSep 5, 2024
    risk 0.27cvss 4.2epss 0.00

    Credentials to access device configuration information stored unencrypted in flash memory. These credentials would allow read-only access to network configuration information and terminal configuration data.

  • CVE-2024-3082MedJul 31, 2024
    risk 0.27cvss 4.2epss 0.00

    A “CWE-256: Plaintext Storage of a Password” affecting the administrative account allows an attacker with physical access to the machine to retrieve the password in cleartext unless specific security measures at other layers (e.g., full-disk encryption) have been enabled.

  • CVE-2024-39878MedJul 1, 2024
    risk 0.27cvss 4.1epss 0.00

    In JetBrains TeamCity before 2024.03.3 private key could be exposed via testing GitHub App Connection

  • CVE-2023-3251MedAug 29, 2023
    risk 0.27cvss 4.1epss 0.01

    A pass-back vulnerability exists where an authenticated, remote attacker with administrator privileges could uncover stored SMTP credentials within the Nessus application.This issue affects Nessus: before 10.6.0.

  • CVE-2022-45859MedMay 3, 2023
    risk 0.27cvss 4.1epss 0.00

    An insufficiently protected credentials vulnerability [CWE-522] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, 8.8.0 all versions, 8.7.0 all versions may allow a local attacker with system access to retrieve users' passwords.

  • CVE-2022-23538MedJan 17, 2023
    risk 0.27cvss 5.2epss 0.01

    github.com/sylabs/scs-library-client is the Go client for the Singularity Container Services (SCS) Container Library Service. When the scs-library-client is used to pull a container image, with authentication, the HTTP Authorization header sent by the client to the library…

  • CVE-2022-29839MedDec 9, 2022
    risk 0.27cvss 4.1epss 0.00

    Insufficiently Protected Credentials vulnerability in the remote backups application on Western Digital My Cloud devices that could allow an attacker who has gained access to a relevant endpoint to use that information to access protected data. This issue affects: Western…

  • CVE-2022-0738MedMar 28, 2022
    risk 0.27cvss 4.2epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 14.6 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. GitLab was leaking user passwords when adding mirrors with SSH credentials under specific…

  • CVE-2020-27413MedDec 7, 2021
    risk 0.27cvss 4.2epss 0.00

    An issue was discovered in Mahavitaran android application 7.50 and below, allows local attackers to read cleartext username and password while the user is logged into the application.