CVE-2019-10398
Vulnerability Description
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
Jenkins Beaker Builder Plugin 1.9 and earlier stored credentials unencrypted in its global configuration file on the Jenkins master where they could be viewed by users with access to the master file system.
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
Claws Mail vCalendar plugin: credentials exposed on interface
CloudForms stores user passwords in recoverable format
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the sig...
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "de...