Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remot
In several versions of JetBrains IntelliJ IDEA Ultimate, creating run configurations for cloud application servers leads
An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in
An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in Artifac
An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in Sona
In pam/gkr-pam-module.c in GNOME Keyring before 3.27.2, the user's password is kept in a session-child process spawned f
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environ
An insufficiently protected credentials vulnerability exists in Jenkins Repository Connector Plugin 1.2.4 and earlier in
A password management issue exists where the Organization authentication username and password were stored in plaintext
Robotronic RunAsSpc 3.7.0.0 protects stored credentials insufficiently, which allows locally authenticated attackers (un
Crestron AM-100 with firmware 1.6.0.2 and AM-101 with firmware 2.7.0.2 stores usernames, passwords, and other configurat
An elevation of privilege vulnerability exists when the Windows Kernel improperly handles key enumeration, aka 'Windows
During HE deployment via cockpit-ovirt, cockpit-ovirt generates an ansible variable file `/var/lib/ovirt-hosted-engine-s
The Android mobile application BlueCats Reveal before 3.0.19 stores the username and password in a clear text file. This
The iOS mobile application BlueCats Reveal before 5.14 stores the username and password in the app cache as base64 encod
In Vijeo Citect 7.30 and 7.40, and CitectSCADA 7.30 and 7.40, a vulnerability has been identified that may allow an auth
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials w
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext
Alarm.com ADC-V522IR 0100b9 devices have Incorrect Access Control, a different issue than CVE-2018-19588. This occurs be
An issue was discovered in TeamViewer 14.2.2558. Updating the product as a non-administrative user requires entering adm
Jenkins Bitbucket OAuth Plugin 0.9 and earlier stored credentials unencrypted in the global config.xml configuration fil
Jenkins Dynatrace Application Monitoring Plugin 2.1.3 and earlier stored credentials unencrypted in its global configura
Jenkins Zulip Plugin 1.1.0 and earlier stored credentials unencrypted in its global configuration file on the Jenkins ma
VMware vCenter Server (6.7.x prior to 6.7 U3, 6.5 prior to 6.5 U3 and 6.0 prior to 6.0 U3j) contains an information disc
A vulnerability has been identified in LOGO! 8 BM (incl. SIPLUS variants) (All versions < V8.3). Unencrypted storage of
types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable
Calamares versions 3.1 through 3.2.10 copies a LUKS encryption keyfile from /crypto_keyfile.bin (mode 0600 owned by root
Redbrick Shift through 3.4.3 allows an attacker to extract authentication tokens of services (such as Gmail, Outlook, et
Fleet before 2.1.2 allows exposure of SMTP credentials.
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel opti
The Loftek Nexus 543 IP Camera stores passwords in cleartext, which allows remote attackers to obtain sensitive informat
webauth before 4.6.1 has authentication credential disclosure
An issue was discovered on Humax Wireless Voice Gateway HGB10R-2 20160817_1855 devices. Admin credentials are sent over
An issue was discovered on Alcatel-Lucent OmniVista 4760 devices, and 8770 devices before 4.1.2. An incorrect web server
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using Plaintex
Artica Proxy 3.06.200056 allows remote attackers to execute arbitrary commands as root by reading the ressources/setting
Kentico v10.0.42 allows Global Administrators to read the cleartext SMTP Password by navigating to the SMTP configuratio
An attacker could retrieve plain-text credentials stored in a XML file on PR100088 Modbus gateway versions prior to Rele
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The proxy server password is di
An issue was discovered in the Web Console in Veritas NetBackup Appliance through 3.1.2. The SMTP password is displayed
In JetBrains Hub versions earlier than 2018.4.11298, the audit events for SMTPSettings show a cleartext password to the
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing pas
When "set system ports console insecure" is enabled, root login is disallowed for Junos OS as expected. However, the roo
eyeDisk implements the unlock feature by sending a cleartext password. The password can be discovered by sniffing USB tr
The Simple - Better Banking application 2.45.0 through 2.45.3 (fixed in 2.46.0) for Android was affected by an informati
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, o
Jenkins TestFairy Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be
Jenkins Crowd Integration Plugin stores credentials unencrypted in the global config.xml configuration file on the Jenki
Users with Site-level permissions can access files containing the username-encrypted passwords of Security Console Globa
Frequently Asked Questions
What is CWE-522?
CWE-522 (CWE-522) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-522?
There are 1,642 CVE records associated with CWE-522 in our database. Of these, 219 are critical severity, 481 are high severity, and 651 are medium severity.
How can I protect against CWE-522 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-522 using AI-powered security agents.
Detect CWE-522 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-522 vulnerabilities across your infrastructure.
Get Started