Описание
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system.
Уязвимые конфигурации
Конфигурация 1Версия от 12.70 (включая) до 14.20 (исключая)
cpe:2.3:a:absolute:secure_access:*:*:*:*:*:*:*:*
EPSS
Процентиль: 3%
0.00016
Низкий
3.4 Low
CVSS3
Дефекты
CWE-532
Связанные уязвимости
CVSS3: 3.4
github
21 день назад
In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system.
EPSS
Процентиль: 3%
0.00016
Низкий
3.4 Low
CVSS3
Дефекты
CWE-532