Show filters
731 Total Results
Displaying 291-300 of 731
Sort by:
Attacker Value
Unknown

CVE-2022-0718

Disclosure Date: August 29, 2022 (last updated February 24, 2025)
A flaw was found in python-oslo-utils. Due to improper parsing, passwords with a double quote ( " ) in them cause incorrect masking in debug logs, causing any part of the password after the double quote to be plaintext.
Attacker Value
Unknown

CVE-2022-27560

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
HCL VersionVault Express exposes administrator credentials.
Attacker Value
Unknown

CVE-2021-20260

Disclosure Date: August 26, 2022 (last updated February 24, 2025)
A flaw was found in the Foreman project. The Datacenter plugin exposes the password through the API to an authenticated local attacker with view_hosts permission. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
Unknown

CVE-2021-43767

Disclosure Date: August 25, 2022 (last updated February 24, 2025)
Odyssey passes to client unencrypted bytes from man-in-the-middle When Odyssey storage is configured to use the PostgreSQL server using 'trust' authentication with a 'clientcert' requirement or to use 'cert' authentication, a man-in-the-middle attacker can inject false responses to the client's first few queries. Despite the use of SSL certificate verification and encryption, Odyssey will pass these results to client as if they originated from valid server. This is similar to CVE-2021-23222 for PostgreSQL.
Attacker Value
Unknown

CVE-2022-38665

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
Jenkins CollabNet Plugins Plugin 2.0.8 and earlier stores a RabbitMQ password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
Attacker Value
Unknown

CVE-2022-38663

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
Jenkins Git Plugin 4.11.4 and earlier does not properly mask (i.e., replace with asterisks) credentials in the build log provided by the Git Username and Password (`gitUsernamePassword`) credentials binding.
Attacker Value
Unknown

CVE-2020-35992

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
Fiserv Prologue through 2020-12-16 does not properly protect the database password. If an attacker were to gain access to the configuration file (specifically, the LogPassword attribute within appconfig.ini), they would be able to decrypt the password stored within the configuration file. This would yield cleartext credentials for the database (to gain access to financial records of customers stored within the database), and in some cases would allow remote login to the database.
Attacker Value
Unknown

CVE-2021-3513

Disclosure Date: August 22, 2022 (last updated February 24, 2025)
A flaw was found in keycloak where a brute force attack is possible even when the permanent lockout feature is enabled. This is due to a wrong error message displayed when wrong credentials are entered. The highest threat from this vulnerability is to confidentiality.
Attacker Value
Unknown

CVE-2021-36783

Disclosure Date: August 19, 2022 (last updated February 24, 2025)
A Insufficiently Protected Credentials vulnerability in SUSE Rancher allows authenticated Cluster Owners, Cluster Members, Project Owners and Project Members to read credentials, passwords and API tokens that have been stored in cleartext and exposed via API endpoints. This issue affects: SUSE Rancher Rancher versions prior to 2.6.4; Rancher versions prior to 2.5.13.
Attacker Value
Unknown

CVE-2022-30944

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via local access.