Vulnerability Description
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netskope | Netskope | <= 91 |
Related Weaknesses (CWE)
References
- https://www.netskope.com/company/security-compliance-and-assurance/security-adviVendor Advisory
- https://www.netskope.com/company/security-compliance-and-assurance/security-adviVendor Advisory
FAQ
What is CVE-2021-44862?
CVE-2021-44862 is a vulnerability with a CVSS score of 8.4 (HIGH). Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists becaus...
How severe is CVE-2021-44862?
CVE-2021-44862 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-44862?
Check the references section above for vendor advisories and patch information. Affected products include: Netskope Netskope.