The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.
2021-09-02T00:15:07.290
2024-11-21T06:06:14.577
Modified
CVSSv3.1: 5.1 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:N/A:N
3.4
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cyberark | credential_provider | < 12.1 | Yes |