PT-2024-13679 · Github · Github
Constantin Schwarz
+1
·
Published
2024-06-20
·
Updated
2024-07-03
·
CVE-2023-49113
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Kiuwan SAST: versions prior to the fixed version
Kiuwan Local Analyzer (KLA) (affected versions not specified)
Description
The Kiuwan Local Analyzer (KLA) Java scanning application contains several hard-coded secrets in plain text format, potentially compromising the confidentiality of scan results. Credentials were found in the JAR files, including
insight.github.user and insight.github.password in the "InsightServicesConfig.properties" file, and an encryption key in the "es/als/security/Encryptor.properties" file. At least one specified username corresponds to a valid GitHub account.Recommendations
For Kiuwan SAST, update to a version that includes the fix for this issue.
For Kiuwan Local Analyzer (KLA), consider removing or securely storing the hard-coded secrets, such as
insight.github.user and insight.github.password, and the encryption key in the "es/als/security/Encryptor.properties" file, until a patch is available.
As a temporary workaround, restrict access to the "lib.engine/insight/optimyth-insight.jar" file and its contents to minimize the risk of exploitation.Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Github