CWE-256
AllowedPlaintext Storage of a Password
Abstraction: Base · Status: Incomplete
The product stores a password in plaintext within resources such as memory or files.
429 vulnerabilities reference this CWE, most recent first.
GHSA-9HRM-54HP-FCPJ
Vulnerability from github – Published: 2026-02-03 18:30 – Updated: 2026-02-03 18:30GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access.
{
"affected": [],
"aliases": [
"CVE-2020-37115"
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-02-03T18:16:11Z",
"severity": "HIGH"
},
"details": "GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users\u0027 usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access.",
"id": "GHSA-9hrm-54hp-fcpj",
"modified": "2026-02-03T18:30:45Z",
"published": "2026-02-03T18:30:45Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-37115"
},
{
"type": "WEB",
"url": "https://download.openeclass.org/files/docs/1.7/CHANGES.txt"
},
{
"type": "WEB",
"url": "https://www.exploit-db.com/exploits/48163"
},
{
"type": "WEB",
"url": "https://www.openeclass.org"
},
{
"type": "WEB",
"url": "https://www.vulncheck.com/advisories/gunet-openeclass-e-learning-platform-plaintext-password-storage"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-9R2G-27GF-RM9W
Vulnerability from github – Published: 2024-08-15 03:30 – Updated: 2024-08-15 03:30IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.
{
"affected": [],
"aliases": [
"CVE-2024-25024"
],
"database_specific": {
"cwe_ids": [
"CWE-256",
"CWE-312"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-08-15T03:15:04Z",
"severity": "MODERATE"
},
"details": "IBM QRadar Suite Software 1.10.12.0 through 1.10.23.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 281430.",
"id": "GHSA-9r2g-27gf-rm9w",
"modified": "2024-08-15T03:30:28Z",
"published": "2024-08-15T03:30:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-25024"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/281430"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7165488"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-9VQF-Q6G6-HPJ7
Vulnerability from github – Published: 2025-03-29 00:31 – Updated: 2025-03-29 00:31IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.
{
"affected": [],
"aliases": [
"CVE-2024-43186"
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-03-29T00:15:23Z",
"severity": "MODERATE"
},
"details": "IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information that is stored locally under certain conditions.",
"id": "GHSA-9vqf-q6g6-hpj7",
"modified": "2025-03-29T00:31:35Z",
"published": "2025-03-29T00:31:35Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43186"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7184980"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C7JC-3J2X-59X8
Vulnerability from github – Published: 2024-12-18 18:30 – Updated: 2024-12-18 18:30IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9
stores user credentials in plain text which can be read by an authenticated user with access to the pod.
{
"affected": [],
"aliases": [
"CVE-2024-52361"
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-12-18T16:15:13Z",
"severity": "MODERATE"
},
"details": "IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 \n\n\n\n\u00a0stores user credentials in plain text which can be read by an authenticated user with access to the pod.",
"id": "GHSA-c7jc-3j2x-59x8",
"modified": "2024-12-18T18:30:52Z",
"published": "2024-12-18T18:30:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52361"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7178587"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-C83J-J8V6-F4GJ
Vulnerability from github – Published: 2026-09-25 15:31 – Updated: 2026-09-25 15:31IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.
{
"affected": [],
"aliases": [
"CVE-2026-84884"
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-25T14:17:19Z",
"severity": "HIGH"
},
"details": "IBM Guardium Data Protection 12.2 stores internal REST service-account passwords in a reversible plaintext-equivalent format. An authenticated attacker who gains access to the stored credential could recover the password and obtain an administrative REST access token.",
"id": "GHSA-c83j-j8v6-f4gj",
"modified": "2026-09-25T15:31:47Z",
"published": "2026-09-25T15:31:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84884"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7288035"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-C8MF-MC3F-2WVC
Vulnerability from github – Published: 2022-06-24 00:00 – Updated: 2022-12-05 21:55Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "com.convertigo.jenkins.plugins:convertigo-mobile-platform"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.1"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2022-34199"
],
"database_specific": {
"cwe_ids": [
"CWE-256",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2022-07-05T22:55:56Z",
"nvd_published_at": "2022-06-23T17:15:00Z",
"severity": "MODERATE"
},
"details": "Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job `config.xml` files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.",
"id": "GHSA-c8mf-mc3f-2wvc",
"modified": "2022-12-05T21:55:06Z",
"published": "2022-06-24T00:00:31Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-34199"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/convertigo-mobile-platform-plugin"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2022-06-22/#SECURITY-2064"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Plaintext Storage of a Password in Jenkins Convertigo Mobile Platform Plugin "
}
GHSA-C9RG-8P7F-JWWP
Vulnerability from github – Published: 2026-03-03 21:31 – Updated: 2026-03-04 15:30An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.
{
"affected": [],
"aliases": [
"CVE-2024-55026"
],
"database_specific": {
"cwe_ids": [
"CWE-256"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-03-03T20:16:41Z",
"severity": "HIGH"
},
"details": "An issue in the reset_pj.cgi endpoint of Weintek cMT-3072XH2 easyweb v2.1.53, OS v20231011 allows unauthorized attackers to execute arbitrary commands via supplying a crafted GET request.",
"id": "GHSA-c9rg-8p7f-jwwp",
"modified": "2026-03-04T15:30:33Z",
"published": "2026-03-03T21:31:15Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-55026"
},
{
"type": "WEB",
"url": "https://gist.github.com/AenganZ/f86ed0da28825a1432ec697f484622de"
},
{
"type": "WEB",
"url": "https://plain-trick-71d.notion.site/weintek-cMT-3072XH2-14687a89c4c181eeb21ad61e0392f34b?pvs=4"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-CCWP-633J-G29V
Vulnerability from github – Published: 2022-05-24 17:27 – Updated: 2022-12-20 22:10ReadyAPI Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job config.xml files as part of its configuration. These project passwords can be viewed by attackers with Extended Read permission or access to the Jenkins controller file system.
ReadyAPI Functional Testing Plugin 1.4 stores project passwords encrypted once affected job configurations are saved again.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 1.3"
},
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:soapui-pro-functional-testing"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "1.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2020-2250"
],
"database_specific": {
"cwe_ids": [
"CWE-256",
"CWE-311"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-20T22:10:51Z",
"nvd_published_at": "2020-09-01T14:15:00Z",
"severity": "MODERATE"
},
"details": "ReadyAPI Functional Testing Plugin 1.3 and earlier stores project passwords unencrypted in job `config.xml` files as part of its configuration. These project passwords can be viewed by attackers with Extended Read permission or access to the Jenkins controller file system.\n\nReadyAPI Functional Testing Plugin 1.4 stores project passwords encrypted once affected job configurations are saved again.",
"id": "GHSA-ccwp-633j-g29v",
"modified": "2022-12-20T22:10:51Z",
"published": "2022-05-24T17:27:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-2250"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/soapui-pro-functional-testing-plugin"
},
{
"type": "WEB",
"url": "https://jenkins.io/security/advisory/2020-09-01/#SECURITY-1631%20(1)"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2020/09/01/3"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Passwords stored in plain text by Jenkins ReadyAPI Functional Testing Plugin"
}
GHSA-CG4H-CFJP-H3X2
Vulnerability from github – Published: 2022-05-24 17:33 – Updated: 2022-12-22 13:50Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global config.xml file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:labmanager"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.2.8"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2020-2319"
],
"database_specific": {
"cwe_ids": [
"CWE-256",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2022-12-22T13:50:16Z",
"nvd_published_at": "2020-11-04T15:15:00Z",
"severity": "LOW"
},
"details": "Jenkins VMware Lab Manager Slaves Plugin 0.2.8 and earlier stores a password unencrypted in the global `config.xml` file on the Jenkins controller, where it can be viewed by users with access to the Jenkins controller file system.",
"id": "GHSA-cg4h-cfjp-h3x2",
"modified": "2022-12-22T13:50:16Z",
"published": "2022-05-24T17:33:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-2319"
},
{
"type": "PACKAGE",
"url": "https://github.com/jenkinsci/labmanager-plugin"
},
{
"type": "WEB",
"url": "https://www.jenkins.io/security/advisory/2020-11-04/#SECURITY-2084"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Password stored in plain text by Jenkins VMware Lab Manager Slaves Plugin"
}
GHSA-CHM8-WP3H-F4M3
Vulnerability from github – Published: 2022-05-24 16:43 – Updated: 2023-10-26 15:33Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file hudson.plugins.jira.JiraProjectProperty.xml on the Jenkins master. These credentials could be viewed by users with access to the Jenkins master file system.
jira-ext Plugin version 0.9 stores credentials encrypted.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.jenkins-ci.plugins:jira-ext"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "0.9"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2019-10302"
],
"database_specific": {
"cwe_ids": [
"CWE-256",
"CWE-522"
],
"github_reviewed": true,
"github_reviewed_at": "2023-05-19T23:46:18Z",
"nvd_published_at": "2019-04-18T17:29:00Z",
"severity": "HIGH"
},
"details": "Jenkins jira-ext Plugin 0.8 and earlier stored credentials unencrypted in its global configuration file `hudson.plugins.jira.JiraProjectProperty.xml` on the Jenkins master. These credentials could be viewed by users with access to the Jenkins master file system.\n\njira-ext Plugin version 0.9 stores credentials encrypted.",
"id": "GHSA-chm8-wp3h-f4m3",
"modified": "2023-10-26T15:33:47Z",
"published": "2022-05-24T16:43:53Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2019-10302"
},
{
"type": "WEB",
"url": "https://github.com/jenkinsci/jira-ext-plugin/commit/e252f4084089e5cfb4c7bad389d3d20f3ec594fb"
},
{
"type": "WEB",
"url": "https://jenkins.io/security/advisory/2019-04-17/#SECURITY-836"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/108045"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Jenkins jira-ext Plugin stores credentials unencrypted"
}
Mitigation
Avoid storing passwords in easily accessible locations.
Mitigation
Consider storing cryptographic hashes of passwords as an alternative to storing in plaintext.
Mitigation
A programmer might attempt to remedy the password management problem by obscuring the password with an encoding function, such as base 64 encoding, but this effort does not adequately protect the password because the encoding can be detected and decoded easily.
No CAPEC attack patterns related to this CWE.