Sensitive Information store in NSClient logs
Vulnerability Description
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-44862
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Netskope credits Ben O’Dea and Josh Wilson from IAG Australia for reporting this vulnerability.
More from Netskope
View All →Affected Vendor
Netskope
View all reports →