Description
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
Published: 2024-07-17
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

This issue is fixed in Zowe CLI 7.23.5 or later, included as part of Zowe 2.16.0 or later.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2350 A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
Github GHSA Github GHSA GHSA-ghgq-x6wc-6jr5 Zowe CLI allows storage of previously entered secure credentials in a plaintext file
References
History

No history.

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zowe

Published:

Updated: 2024-08-01T21:45:38.354Z

Reserved: 2024-07-17T14:41:37.247Z

Link: CVE-2024-6833

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.354Z

cve-icon NVD

Status : Deferred

Published: 2024-07-17T15:15:14.783

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-6833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.