VYPR

CWE-523

Unprotected Transport of Credentials

BaseIncomplete

Description

Login pages do not use adequate measures to protect the user name and password while they are in transit from the client to the server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-102

CVEs mapped to this weakness (25)

page 2 of 2
  • CVE-2024-1102MedApr 25, 2024
    risk 0.35cvss 6.5epss 0.01

    A vulnerability was found in jberet-core logging. An exception in 'dbProperties' might display user credentials such as the username and password for the database-connection.

  • CVE-2023-28708MedMar 22, 2023
    risk 0.21cvss 4.3epss 0.02

    When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did…

  • CVE-2026-8668LowJun 18, 2026
    risk 0.15cvss epss 0.00

    A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.  The credential has been rotated and replaced with per-tenant access in subsequent versions, eliminating…

  • CVE-2026-56587LowJul 21, 2026
    risk 0.00cvss 3.7epss 0.00

    HCL IEM was affected with Strict transport security not enforced. It may enable attackers to perform SSL stripping or man-in-the-middle attacks and compromise secure communications.

  • CVE-2025-57800HigAug 22, 2025
    risk 0.00cvss 8.8epss 0.00

    Audiobookshelf is an open-source self-hosted audiobook server. In versions 2.6.0 through 2.26.3, the application does not properly restrict redirect callback URLs during OIDC authentication. An attacker can craft a login link that causes Audiobookshelf to store an arbitrary…