CVE-2020-2145
Vulnerability Description
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
Claws Mail vCalendar plugin: credentials exposed on interface
CloudForms stores user passwords in recoverable format
rubygem-hammer_cli_foreman: File /etc/hammer/cli.modules.d/foreman.yml world readable
signond before 8.57+15.04.20141127.1-0ubuntu1, as used in Ubuntu Touch, did not properly restrict applications from querying oath tokens due to incorrect checks and the missing installation of the sig...
Ansible before 1.5.5 sets 0644 permissions for sources.list, which might allow local users to obtain sensitive credential information in opportunistic circumstances by reading a file that uses the "de...