A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
References
Link | Resource |
---|---|
https://github.com/zowe/zowe-cli/packages/imperative | Broken Link |
Configurations
History
23 Aug 2024, 13:44
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
First Time |
Zowe zowe Cli
Zowe |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.5 |
CWE | CWE-922 | |
CPE | cpe:2.3:a:zowe:zowe_cli:*:*:*:*:*:*:*:* | |
References | () https://github.com/zowe/zowe-cli/packages/imperative - Broken Link |
19 Jul 2024, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-19 11:15
Updated : 2024-08-23 13:44
NVD link : CVE-2024-6916
Mitre link : CVE-2024-6916
CVE.ORG link : CVE-2024-6916
JSON object : View
Products Affected
zowe
- zowe_cli
CWE
CWE-922
Insecure Storage of Sensitive Information