PT-2022-19693 · Qualys · Qualys Cloud Agent
Bryan Li
+3
·
Published
2022-08-18
·
Updated
2024-08-03
·
CVE-2022-29550
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Qualys Cloud Agent version 4.8.0-49
Description
An issue was discovered in Qualys Cloud Agent where it writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may unexpectedly write credentials from environment variables to disk in cleartext. Although there are no common circumstances in which the log file can be read by a user other than root, the file contents could be exposed through site-specific operational practices. The vendor does not characterize this as a vulnerability because the ps data collection is intentional and would only capture credentials on a machine already affected by a specific weakness.
Recommendations
For Qualys Cloud Agent version 4.8.0-49, consider restricting access to the /var/log/qualys/qualys-cloud-agent-scan.log file to minimize the risk of exposure. As a temporary workaround, consider disabling the collection of "ps auxwwe" output until a more secure solution is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qualys Cloud Agent