We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2024-6916

Zowe CLI --show-inputs-only displays securely stored properties



AssignerZowe
Reserved2024-07-19
Published2024-07-19
Updated2024-08-01

Description

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.



MEDIUM: 5.9CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N/E:P/RL:O/RC:C/CR:M/IR:X/AR:X/MAV:L/MAC:L/MPR:L/MUI:R/MS:C/MC:H/MI:N/MA:N

Problem types

CWE-257: Storing Passwords in a Recoverable Format

CWE-1295: Debug Messages Revealing Unnecessary Information

Product status

5.1.0 before 5.22.6
affected

Credits

Broadcom Inc. 0x400168ebf0

References

https://github.com/zowe/zowe-cli/packages/imperative product

cve.org CVE-2024-6916

nvd.nist.gov CVE-2024-6916

Download JSON

Share this page
https://cve.threatint.com
Subscribe to our newsletter to learn more about our work.