PT-2021-15370 · Unknown · Guided Configuration
Published
2021-09-14
·
Updated
2021-09-24
·
CVE-2021-23046
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Guided Configuration versions prior to 8.0.0
Description
The issue arises when a configuration containing secure properties is created and deployed from Access Guided Configuration (AGC), resulting in secure properties being logged in restnoded logs. This occurs on all versions of Guided Configuration before 8.0.0.
Recommendations
For versions prior to 8.0.0, update to version 8.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the restnoded logs to minimize the risk of exploitation.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Guided Configuration