Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-31665 Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
Fixes

Solution

Upgrade to the latest version available.


Workaround

No workaround given by the vendor.

History

Fri, 02 May 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Netskope

Published:

Updated: 2025-05-02T18:47:57.929Z

Reserved: 2021-12-13T00:00:00.000Z

Link: CVE-2021-44862

cve-icon Vulnrichment

Updated: 2024-08-04T04:32:13.203Z

cve-icon NVD

Status : Modified

Published: 2022-11-03T20:15:24.700

Modified: 2024-11-21T06:31:37.780

Link: CVE-2021-44862

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.