CVE-2021-44862

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
03/11/2022
Last modified:
25/10/2023

Description

Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.<br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netskope:netskope:*:*:*:*:*:*:*:* 91 (including)