Insecure Storage of Sensitive Information
CVE-2024-6916
Summary
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
- LOW
- LOCAL
- NONE
- CHANGED
- REQUIRED
- LOW
- HIGH
- NONE
CWE-922 - Insecure Storage of Sensitive Information
The software stores sensitive information without properly limiting read or write access by unauthorized actors.
References
Advisory Timeline
- Published