github.comproduct
https://github.com/zowe/zowe-cli CVE-2024-6833
Zowe CLI Auto-Init Leaks Credentials Locally
Description
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 17, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 7.18.0 to < 7.23.5 | affected | |
@zowe/cliBrowse npm / @zowe/cli | GitHub Advisory | 7.18.0 to < 7.23.5 · Fixed in 7.23.5 | affected |
References
3github.com
https://github.com/zowe/zowe-cli/commit/6778da5e03c65dfcd3e6e4b4097b94d9fbd5d01b nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-6833