Skip to main content

Plaintext Storage of a Password

CVE-2024-6833

Severity Medium
Score 5.9/10

Summary

A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an "auto-init" operation. This issue affects the package @zowe/cli versions 7.18.0 through 7.23.4 and 8.0.0-next.202311152026 through 8.0.0-next.202403061549.

  • LOW
  • LOCAL
  • NONE
  • CHANGED
  • REQUIRED
  • LOW
  • HIGH
  • NONE

CWE-256 - Plaintext Storage of a Password

Storing a password in plaintext may result in a system compromise.

Advisory Timeline

  • Published