Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ww6p-8hpv-p4mc

Опубликовано: 04 нояб. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.

Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.

EPSS

Процентиль: 16%
0.0005
Низкий

7.8 High

CVSS3

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 8.4
nvd
больше 3 лет назад

Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.

EPSS

Процентиль: 16%
0.0005
Низкий

7.8 High

CVSS3

Дефекты

CWE-532