Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r659-cjpw-fq42

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

EPSS

Процентиль: 7%
0.00026
Низкий

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 6
nvd
больше 5 лет назад

"BigFix Platform is storing clear text credentials within the system's memory. An attacker who is able to gain administrative privileges can use a program to create a memory dump and extract the credentials. These credentials can be used to pivot further into the environment. The principle of least privilege should be applied to all BigFix deployments, limiting administrative access."

EPSS

Процентиль: 7%
0.00026
Низкий

Дефекты

CWE-522