CVE-2021-31797

Severity CVSS v4.0:
Pending analysis
Type:
CWE-331 Insufficient Entropy
Publication date:
02/09/2021
Last modified:
08/08/2023

Description

The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cyberark:credential_provider:*:*:*:*:*:*:*:* 12.1 (excluding)