Description

A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE List7.18.0 to < 7.23.5affected
GitHub Advisory7.18.0 to < 7.23.5 · Fixed in 7.23.5affected

References

3