A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.

Project Subscriptions

No data.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2350 A vulnerability in Zowe CLI allows local, privileged actors to store previously entered secure credentials in a plaintext file as part of an auto-init operation.
Github GHSA Github GHSA GHSA-ghgq-x6wc-6jr5 Zowe CLI allows storage of previously entered secure credentials in a plaintext file
Fixes

Solution

This issue is fixed in Zowe CLI 7.23.5 or later, included as part of Zowe 2.16.0 or later.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Zowe

Published:

Updated: 2024-08-01T21:45:38.354Z

Reserved: 2024-07-17T14:41:37.247Z

Link: CVE-2024-6833

cve-icon Vulnrichment

Updated: 2024-08-01T21:45:38.354Z

cve-icon NVD

Status : Deferred

Published: 2024-07-17T15:15:14.783

Modified: 2026-04-15T00:35:42.020

Link: CVE-2024-6833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.