CVE-2024-6916

A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
Configurations

Configuration 1 (hide)

cpe:2.3:a:zowe:zowe_cli:*:*:*:*:*:*:*:*

History

21 Nov 2024, 09:50

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.5
v2 : unknown
v3 : 5.9
References () https://github.com/zowe/zowe-cli/packages/imperative - Broken Link () https://github.com/zowe/zowe-cli/packages/imperative - Broken Link

23 Aug 2024, 13:44

Type Values Removed Values Added
CWE CWE-922
First Time Zowe zowe Cli
Zowe
CVSS v2 : unknown
v3 : 5.9
v2 : unknown
v3 : 5.5
Summary
  • (es) Una vulnerabilidad en Zowe CLI permite a actores locales privilegiados mostrar propiedades almacenadas de forma segura en texto plano dentro de una terminal usando el indicador '--show-inputs-only'.
CPE cpe:2.3:a:zowe:zowe_cli:*:*:*:*:*:*:*:*
References () https://github.com/zowe/zowe-cli/packages/imperative - () https://github.com/zowe/zowe-cli/packages/imperative - Broken Link

19 Jul 2024, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-19 11:15

Updated : 2024-11-21 09:50


NVD link : CVE-2024-6916

Mitre link : CVE-2024-6916

CVE.ORG link : CVE-2024-6916


JSON object : View

Products Affected

zowe

  • zowe_cli
CWE
CWE-922

Insecure Storage of Sensitive Information