Show filters
593 Total Results
Displaying 191-200 of 593
Sort by:
Attacker Value
Unknown

CVE-2022-34803

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission (config.xml), or access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34802

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34800

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34799

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-31887

Disclosure Date: June 28, 2022 (last updated February 24, 2025)
Marval MSM v14.19.0.12476 has a 0-Click Account Takeover vulnerability which allows an attacker to change any user's password in the organization, this means that the user can also escalate achieve Privilege Escalation by changing the administrator password.
Attacker Value
Unknown

CVE-2022-31085

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
LDAP Account Manager (LAM) is a webfrontend for managing entries (e.g. users, groups, DHCP settings) stored in an LDAP directory. In versions prior to 8.0 the session files include the LDAP user name and password in clear text if the PHP OpenSSL extension is not installed or encryption is disabled by configuration. This issue has been fixed in version 8.0. Users unable to upgrade should install the PHP OpenSSL extension and make sure session encryption is enabled in LAM main configuration.
Attacker Value
Unknown

CVE-2022-2221

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Information Exposure vulnerability in My Account Settings of Devolutions Remote Desktop Manager before 2022.1.8 allows authenticated users to access credentials of other users. This issue affects: Devolutions Remote Desktop Manager versions prior to 2022.1.8.
Attacker Value
Unknown

CVE-2022-28167

Disclosure Date: June 27, 2022 (last updated February 24, 2025)
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
Attacker Value
Unknown

CVE-2022-34213

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins Squash TM Publisher (Squash4Jenkins) Plugin 1.0.0 and earlier stores passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-34202

Disclosure Date: June 23, 2022 (last updated February 23, 2025)
Jenkins EasyQA Plugin 1.0 and earlier stores user passwords unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.