PT-2022-15644 · Stormshield · Stormshield Sso Agent

Published

2022-01-17

·

Updated

2022-01-24

·

CVE-2022-22703

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Stormshield SSO Agent versions 2.x through 2.1.0 Stormshield SSO Agent versions 3.x through 3.0.1
Description The issue concerns the storage of sensitive information in log files. Specifically, the cleartext user password and PSK are contained in the log file of the .exe installer.
Recommendations For Stormshield SSO Agent versions 2.x through 2.1.0, update to version 2.1.1 or later. For Stormshield SSO Agent versions 3.x through 3.0.1, update to version 3.0.2 or later.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22703

Affected Products

Stormshield Sso Agent