CVE-2021-44862
03.11.2022, 20:15
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.Enginsight
Vendor | Product | Version |
---|---|---|
netskope | netskope | 𝑥 ≤ 91 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References