Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-44862


Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.


Published

2022-11-03T20:15:24.700

Last Modified

2024-11-21T06:31:37.780

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.4 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-532
  • Type: Primary
    CWE-532

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netskope netskope ≤ 91 Yes

References