PT-2019-20062 · Pem · Pem

Published

2019-06-04

·

Updated

2019-06-04

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions pem versions prior to 1.13.2
Description The issue exposes sensitive data when the readPkcs12 function is used. This function reads certificate and key data from a pkcs12 file using the encryption password, creating a globally readable file with the password in the temporary directory. The file containing the password is not cleaned up after use, allowing access to the pkcs12 password to other users with read access to the system.
Recommendations Update to version 1.13.2 or later.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-PGCR-7WM4-MCV6

Affected Products

Pem