Show filters
485 Total Results
Displaying 121-130 of 485
Sort by:
Attacker Value
Unknown

CVE-2021-3681

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
Attacker Value
Unknown

CVE-2022-27179

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
Attacker Value
Unknown

CVE-2022-29052

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-24978

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
Attacker Value
Unknown

CVE-2022-28651

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields
Attacker Value
Unknown

CVE-2021-45892

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
An issue was discovered in Softwarebuero Zauner ARC 4.2.0.4. There is storage of Passwords in a Recoverable Format.
Attacker Value
Unknown

CVE-2021-32978

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The programming protocol allows for a previously entered password and lock state to be read by an attacker. If the previously entered password was successful, the attacker can then use the password to unlock Automation Direct CLICK PLC CPU Modules: C0-1x CPUs with firmware prior to v3.00.
Attacker Value
Unknown

CVE-2022-26856

Disclosure Date: April 04, 2022 (last updated February 23, 2025)
Dell EMC Repository Manager version 3.4.0 contains a plain-text password storage vulnerability. A local attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application's database with privileges of the compromised account.
Attacker Value
Unknown

CVE-2021-33024

Disclosure Date: April 01, 2022 (last updated February 23, 2025)
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.
Attacker Value
Unknown

CVE-2022-26948

Disclosure Date: March 30, 2022 (last updated February 23, 2025)
The Archer RSS feed integration for Archer 6.x through 6.9 SP1 (6.9.1.0) is affected by an insecure credential storage vulnerability. A malicious attacker may obtain access to credential information to use it in further attacks.