Vulnerabilities > Insufficiently Protected Credentials

DATE CVE VULNERABILITY TITLE RISK
2019-09-12 CVE-2019-10398 Insufficiently Protected Credentials vulnerability in Jenkins Beaker Builder
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.5
2019-09-11 CVE-2019-11769 Insufficiently Protected Credentials vulnerability in Teamviewer 14.2.2558
An issue was discovered in TeamViewer 14.2.2558.
local
low complexity
teamviewer CWE-522
7.8
2019-09-05 CVE-2019-13349 Insufficiently Protected Credentials vulnerability in Knowage-Suite Knowage
In Knowage through 6.1.1, an authenticated user that accesses the users page will obtain all user password hashes.
network
low complexity
knowage-suite CWE-522
4.9
2019-08-28 CVE-2019-13348 Insufficiently Protected Credentials vulnerability in ENG Knowage
In Knowage through 6.1.1, an authenticated user who accesses the datasources page will gain access to any data source credentials in cleartext, which includes databases.
network
low complexity
eng CWE-522
8.8
2019-08-20 CVE-2019-10960 Insufficiently Protected Credentials vulnerability in Zebra products
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options.
network
low complexity
zebra CWE-522
7.5
2019-08-20 CVE-2019-3753 Insufficiently Protected Credentials vulnerability in Dell products
Dell EMC PowerConnect 8024, 7000, M6348, M6220, M8024 and M8024-K running firmware versions prior to 5.1.15.2 contain a plain-text password storage vulnerability.
network
low complexity
dell CWE-522
6.5
2019-08-14 CVE-2019-15052 Insufficiently Protected Credentials vulnerability in Gradle
The HTTP client in Gradle before 5.6 sends authentication credentials originally destined for the configured host.
network
low complexity
gradle CWE-522
critical
9.8
2019-08-07 CVE-2019-10385 Insufficiently Protected Credentials vulnerability in Jenkins Eggplant
Jenkins eggPlant Plugin 2.2 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
network
low complexity
jenkins CWE-522
6.5
2019-08-07 CVE-2019-10379 Insufficiently Protected Credentials vulnerability in Google Cloud Messaging Notification 1.0
Jenkins Google Cloud Messaging Notification Plugin 1.0 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
google CWE-522
6.5
2019-08-07 CVE-2019-10378 Insufficiently Protected Credentials vulnerability in Jenkins Testlink
Jenkins TestLink Plugin 3.16 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.3