PT-2022-19693 · Qualys · Qualys Cloud Agent

Bryan Li

+3

·

Published

2022-08-18

·

Updated

2024-08-03

·

CVE-2022-29550

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Qualys Cloud Agent version 4.8.0-49
Description An issue was discovered in Qualys Cloud Agent where it writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may unexpectedly write credentials from environment variables to disk in cleartext. Although there are no common circumstances in which the log file can be read by a user other than root, the file contents could be exposed through site-specific operational practices. The vendor does not characterize this as a vulnerability because the ps data collection is intentional and would only capture credentials on a machine already affected by a specific weakness.
Recommendations For Qualys Cloud Agent version 4.8.0-49, consider restricting access to the /var/log/qualys/qualys-cloud-agent-scan.log file to minimize the risk of exposure. As a temporary workaround, consider disabling the collection of "ps auxwwe" output until a more secure solution is available. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Insertion into Log File

Weakness Enumeration

Related Identifiers

CVE-2022-29550

Affected Products

Qualys Cloud Agent