Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-08-20 CVE-2019-10960 Insufficiently Protected Credentials vulnerability in Zebra products
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options.
network
low complexity
zebra CWE-522
7.5
2019-08-20 CVE-2019-3753 Insufficiently Protected Credentials vulnerability in Dell products
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability.
network
low complexity
dell CWE-522
6.5
2019-08-14 CVE-2019-15052 Insufficiently Protected Credentials vulnerability in Gradle
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host.
network
low complexity
gradle CWE-522
critical
9.8
2019-08-07 CVE-2019-10385 Insufficiently Protected Credentials vulnerability in Jenkins Eggplant
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-08-07 CVE-2019-10379 Insufficiently Protected Credentials vulnerability in Google Cloud Messaging Notification 1.0
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
google CWE-522
6.5
2019-08-07 CVE-2019-10378 Insufficiently Protected Credentials vulnerability in Jenkins Testlink
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.3
2019-08-06 CVE-2019-14709 Insufficiently Protected Credentials vulnerability in Microdigital products
A cleartext password storage issue was discovered on MicroDigital N-series cameras with firmware through 6400.0.8.5.
network
low complexity
microdigital CWE-522
critical
9.8
2019-07-31 CVE-2019-10366 Insufficiently Protected Credentials vulnerability in Jenkins Skytap Cloud CI
Jenkins Skytap Cloud CI Plugin 2.06 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-07-31 CVE-2019-10361 Insufficiently Protected Credentials vulnerability in Jenkins M2Release
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.5
2019-07-31 CVE-2019-10345 Insufficiently Protected Credentials vulnerability in Jenkins Configuration AS Code
Jenkins Configuration as Code Plugin 1.20 and earlier did not treat the proxy password as a secret to be masked when logging or encrypted for export.
local
low complexity
jenkins CWE-522
5.5