Vulnerabilities > Cleartext Storage of Sensitive Information

DATE CVE VULNERABILITY TITLE RISK
2019-10-16 CVE-2019-10440 Cleartext Storage of Sensitive Information vulnerability in Jenkins Neoload
Jenkins NeoLoad Plugin 2.2.5 and earlier stored credentials unencrypted in its global configuration file and in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-312
8.8
2019-10-14 CVE-2019-3767 Cleartext Storage of Sensitive Information vulnerability in Dell Imageassist
Dell ImageAssist versions prior to 8.7.15 contain an information disclosure vulnerability.
local
low complexity
dell CWE-312
8.2
2019-10-09 CVE-2019-15023 Cleartext Storage of Sensitive Information vulnerability in Zingbox Inspector
A security vulnerability exists in Zingbox Inspector versions 1.294 and earlier, that results in passwords for 3rd party integrations being stored in cleartext in device configuration.
network
low complexity
zingbox CWE-312
7.5
2019-10-08 CVE-2019-17106 Cleartext Storage of Sensitive Information vulnerability in Centreon web
In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.
network
low complexity
centreon CWE-312
6.5
2019-10-01 CVE-2019-10433 Cleartext Storage of Sensitive Information vulnerability in Jenkins Dingding
Jenkins Dingding[??] Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
local
low complexity
jenkins CWE-312
3.3
2019-09-25 CVE-2019-10430 Cleartext Storage of Sensitive Information vulnerability in Jenkins Neuvector vulnerability Scanner
Jenkins NeuVector Vulnerability Scanner Plugin 1.5 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-312
5.5
2019-09-24 CVE-2019-4566 Cleartext Storage of Sensitive Information vulnerability in IBM Security KEY Lifecycle Manager
IBM Security Key Lifecycle Manager 3.0 and 3.0.1 stores user credentials in plain in clear text which can be read by a local user.
local
low complexity
ibm CWE-312
5.5
2019-09-05 CVE-2019-15947 Cleartext Storage of Sensitive Information vulnerability in Bitcoin Core 0.18.0
In Bitcoin Core 0.18.0, bitcoin-qt stores wallet.dat data unencrypted in memory.
network
low complexity
bitcoin CWE-312
7.5
2019-08-23 CVE-2019-15508 Cleartext Storage of Sensitive Information vulnerability in Octopus Server and Tentacle
In Octopus Tentacle versions 3.0.8 to 5.0.0, when a web request proxy is configured, an authenticated user (in certain limited OctopusPrintVariables circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext.
network
low complexity
octopus CWE-312
6.5
2019-08-23 CVE-2019-15507 Cleartext Storage of Sensitive Information vulnerability in Octopus Server
In Octopus Deploy versions 2018.8.4 to 2019.7.6, when a web request proxy is configured, an authenticated user (in certain limited special-characters circumstances) could trigger a deployment that writes the web request proxy password to the deployment log in cleartext.
network
low complexity
octopus CWE-312
6.5