Password in configuration file

   - external/cwe/cwe-256
   - external/cwe/cwe-260
   - external/cwe/cwe-313
   - javascript-security-extended.qls
   - javascript-security-and-quality.qls

Storing a plaintext password in a configuration file allows anyone who can read the file to access the password-protected resources. Therefore it is a common attack vector.


Passwords stored in configuration files should always be encrypted.


