Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-07-29 CVE-2019-1020009 Insufficiently Protected Credentials vulnerability in Kolide Fleet 2.0.2/2.1.0/2.1.1
Fleet before 2.1.2 allows exposure of SMTP credentials.
network
low complexity
kolide CWE-522
7.5
2019-07-19 CVE-2019-1010241 Insufficiently Protected Credentials vulnerability in Jenkins Credentials Binding 1.17
Jenkins Credentials Binding Plugin Jenkins 1.17 is affected by: CWE-257: Storing Passwords in a Recoverable Format.
network
low complexity
jenkins CWE-522
6.5
2019-07-17 CVE-2019-8932 Insufficiently Protected Credentials vulnerability in Rdbrck Shift
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, etc.) used in the application.
network
low complexity
rdbrck CWE-522
7.5
2019-07-15 CVE-2019-1010308 Insufficiently Protected Credentials vulnerability in Aquaverde Aquarius CMS
Aquaverde GmbH Aquarius CMS prior to version 4.1.1 is affected by: Incorrect Access Control.
network
low complexity
aquaverde CWE-522
critical
9.8
2019-07-11 CVE-2019-9657 Insufficiently Protected Credentials vulnerability in Alarm Adc-V522Ir Firmware 0100B9
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588.
local
low complexity
alarm CWE-522
7.8
2019-07-11 CVE-2019-10347 Insufficiently Protected Credentials vulnerability in Jenkins Mashup Portlets
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
8.8
2019-07-08 CVE-2019-12171 Insufficiently Protected Credentials vulnerability in Dropbox 71.4.108.0
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation.
local
low complexity
dropbox CWE-522
7.8
2019-07-08 CVE-2019-13400 Insufficiently Protected Credentials vulnerability in Fortinet Fcm-Mb40 Firmware 1.2.0.0
Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext.
network
low complexity
fortinet CWE-522
critical
9.8
2019-07-03 CVE-2019-9873 Insufficiently Protected Credentials vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating Task Servers configurations leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
low complexity
jetbrains CWE-522
critical
9.8
2019-07-03 CVE-2019-9872 Insufficiently Protected Credentials vulnerability in Jetbrains Intellij Idea
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads to saving a cleartext unencrypted record of the server credentials in the IDE configuration files.
network
high complexity
jetbrains CWE-522
8.1