NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.
2023-08-03T17:15:11.527
2024-11-21T07:49:40.013
Modified
CVSSv3.1: 4.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nvidia | omniverse_launcher | < 1.8.11 | Yes |
Application | nvidia | omniverse_launcher | < 1.8.11 | Yes |