Netskope client is impacted by a vulnerability where an...
High severity
Unreviewed
Published
Nov 4, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2023
Description
Published by the National Vulnerability Database
Nov 3, 2022
Published to the GitHub Advisory Database
Nov 4, 2022
Last updated
Feb 2, 2023
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
References