We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Assigner | Zowe |
Reserved | 2024-07-19 |
Published | 2024-07-19 |
Updated | 2024-08-01 |
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C/CR:M/IR:X/AR:X/MAV:L/MAC:L/MPR:L/MUI:R/MS:C/MC:H/MI:N/MA:N |
CWE-257: Storing Passwords in a Recoverable Format
CWE-1295: Debug Messages Revealing Unnecessary Information
Broadcom Inc.
https://github.com/zowe/zowe-cli/packages/imperative