Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8q6-g23p-58gh

Опубликовано: 11 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on Windows. This issue does not affect the GlobalProtect app on other platforms.

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on Windows. This issue does not affect the GlobalProtect app on other platforms.

EPSS

Процентиль: 16%
0.00051
Низкий

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 3.3
nvd
почти 4 года назад

An information exposure through log file vulnerability exists in the Palo Alto Networks GlobalProtect app on Windows that logs the cleartext credentials of the connecting GlobalProtect user when authenticating using Connect Before Logon feature. This issue impacts GlobalProtect App 5.2 versions earlier than 5.2.9 on Windows. This issue does not affect the GlobalProtect app on other platforms.

EPSS

Процентиль: 16%
0.00051
Низкий

Дефекты

CWE-532