Show filters
609 Total Results
Displaying 221-230 of 609
Sort by:
Attacker Value
Unknown
CVE-2020-28865
Disclosure Date: June 16, 2022 (last updated February 23, 2025)
An issue was discovered in PowerJob through 3.2.2, allows attackers to change arbitrary user passwords via the id parameter to /appinfo/save.
0
Attacker Value
Unknown
CVE-2022-31044
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
Rundeck is an open source automation service with a web console, command line tools and a WebAPI. The Key Storage converter plugin mechanism was not enabled correctly in Rundeck 4.2.0 and 4.2.1, resulting in use of the encryption layer for Key Storage possibly not working. Any credentials created or overwritten using Rundeck 4.2.0 or 4.2.1 might result in them being written in plaintext to the backend storage. This affects those using any `Storage Converter` plugin. Rundeck 4.3.1 and 4.2.2 have fixed the code and upon upgrade will re-encrypt any plain text values. Version 4.3.0 does not have the vulnerability, but does not include the patch to re-encrypt plain text values if 4.2.0 or 4.2.1 were used. To prevent plaintext credentials from being stored in Rundeck 4.2.0/4.2.1, write access to key storage can be disabled via ACLs. After upgrading to 4.3.1 or later, write access can be restored.
0
Attacker Value
Unknown
CVE-2022-21184
Disclosure Date: June 15, 2022 (last updated February 23, 2025)
An information disclosure vulnerability exists in the License registration functionality of Bachmann Visutec GmbH Atvise 3.5.4, 3.6 and 3.7. A plaintext HTTP request can lead to a disclosure of login credentials. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-30231
Disclosure Date: June 14, 2022 (last updated February 23, 2025)
A vulnerability has been identified in SICAM GridEdge Essential ARM (All versions < V2.6.6), SICAM GridEdge Essential Intel (All versions < V2.6.6), SICAM GridEdge Essential with GDS ARM (All versions < V2.6.6), SICAM GridEdge Essential with GDS Intel (All versions < V2.6.6). The affected software discloses password hashes of other users upon request. This could allow an authenticated user to retrieve another users password hash.
0
Attacker Value
Unknown
CVE-2022-32518
Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32520. Affected Products: Data Center Expert (Versions prior to V7.9.0)
0
Attacker Value
Unknown
CVE-2022-32519
Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-257: Storing Passwords in a Recoverable Format vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. Affected Products: Data Center Expert (Versions prior to V7.9.0)
0
Attacker Value
Unknown
CVE-2022-32520
Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could result in unwanted access to a DCE instance when performed over a network by a malicious third-party. This CVE is unique from CVE-2022-32518. Affected Products: Data Center Expert (Versions prior to V7.9.0)
0
Attacker Value
Unknown
CVE-2022-30587
Disclosure Date: June 06, 2022 (last updated February 23, 2025)
Gradle Enterprise through 2022.2.2 has Incorrect Access Control that leads to information disclosure.
0
Attacker Value
Unknown
CVE-2022-27774
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
An insufficiently protected credentials vulnerability exists in curl 4.9 to and include curl 7.82.0 are affected that could allow an attacker to extract credentials when follows HTTP(S) redirects is used with authentication could leak credentials to other services that exist on different protocols or port numbers.
0
Attacker Value
Unknown
CVE-2022-27776
Disclosure Date: June 02, 2022 (last updated February 23, 2025)
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
0