Plaintext Storage of a Password
CVE-2024-6833
Summary
A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an "auto-init" operation. This issue affects the package @zowe/cli versions 7.18.0 through 7.23.4 and 8.0.0-next.202311152026 through 8.0.0-next.202403061549.
- LOW
- LOCAL
- NONE
- CHANGED
- REQUIRED
- LOW
- HIGH
- NONE
CWE-256 - Plaintext Storage of a Password
Storing a password in plaintext may result in a system compromise.
References
Advisory Timeline
- Published