Show filters
500 Total Results
Displaying 131-140 of 500
Sort by:
Attacker Value
Unknown

CVE-2022-1766

Disclosure Date: April 29, 2022 (last updated February 24, 2025)
Anchore Enterprise anchorectl version 0.1.4 improperly stored credentials when generating a Software Bill of Materials. anchorectl will add the credentials used to access Anchore Enterprise API in the Software Bill of Materials (SBOM) generated by anchorectl. Users of anchorectl version 0.1.4 should upgrade to anchorectl version 0.1.5 to resolve this issue.
Attacker Value
Unknown

CVE-2022-24867

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldap_pass is not filtered and when you look at the source code of the rendered page, we can see the password for the root dn. Users are advised to upgrade. There is no known workaround for this issue.
Attacker Value
Unknown

CVE-2022-1342

Disclosure Date: April 21, 2022 (last updated February 23, 2025)
A lack of password masking in Devolutions Remote Desktop Manager allows physically proximate attackers to observe sensitive data. A caching issue can cause sensitive fields to sometimes stay revealed when closing and reopening a panel, which could lead to involuntarily disclosing sensitive information. This issue affects: Devolutions Remote Desktop Manager 2022.1.24 version and prior versions.
Attacker Value
Unknown

CVE-2022-22557

Disclosure Date: April 19, 2022 (last updated February 23, 2025)
PowerStore contains Plain-Text Password Storage Vulnerability in PowerStore X & T environments running versions 2.0.0.x and 2.0.1.x A locally authenticated attacker could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.
Attacker Value
Unknown

CVE-2022-29457

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADSelfService Plus before 6121, ADAuditPlus 7060, Exchange Reporter Plus 5701, and ADManagerPlus 7131 allow NTLM Hash disclosure during certain storage-path configuration steps.
Attacker Value
Unknown

CVE-2021-3681

Disclosure Date: April 18, 2022 (last updated February 23, 2025)
A flaw was found in Ansible Galaxy Collections. When collections are built manually, any files in the repository directory that are not explicitly excluded via the ``build_ignore`` list in "galaxy.yml" include files in the ``.tar.gz`` file. This contains sensitive info, such as the user's Ansible Galaxy API key and any secrets in ``ansible`` or ``ansible-playbook`` verbose output without the``no_log`` redaction. Currently, there is no way to deprecate a Collection Or delete a Collection Version. Once published, anyone who downloads or installs the collection can view the secrets.
Attacker Value
Unknown

CVE-2022-27179

Disclosure Date: April 14, 2022 (last updated February 23, 2025)
A malicious actor having access to the exported configuration file may obtain the stored credentials and thereby gain access to the protected resource. If the same passwords were used for other resources, further such assets may be compromised.
Attacker Value
Unknown

CVE-2022-29052

Disclosure Date: April 12, 2022 (last updated February 23, 2025)
Jenkins Google Compute Engine Plugin 4.3.8 and earlier stores private keys unencrypted in cloud agent config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-24978

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Zoho ManageEngine ADAudit Plus before 7055 allows authenticated Privilege Escalation on Integrated products. This occurs because a password field is present in a JSON response.
Attacker Value
Unknown

CVE-2022-28651

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
In JetBrains IntelliJ IDEA before 2021.3.3 it was possible to get passwords from protected fields