CVE-2021-44862: Sensitive Information store in NSClient logs
Netskope client is impacted by a vulnerability where an authenticated, local attacker can view sensitive information stored in NSClient logs which should be restricted. The vulnerability exists because the sensitive information is not masked/scrubbed before writing in the logs. A malicious user can use the sensitive information to download data and impersonate another user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-44862.
What is the severity of CVE-2021-44862?
The severity of CVE-2021-44862 is high with a score of 7.8.
What is the affected software for CVE-2021-44862?
The affected software for CVE-2021-44862 is Netskope client version up to 91.
How does CVE-2021-44862 impact Netskope client?
CVE-2021-44862 allows an authenticated local attacker to view sensitive information stored in NSClient logs, which should be restricted.
Is there a fix available for CVE-2021-44862?
Yes, it is recommended to update Netskope client to a version that includes a fix for CVE-2021-44862.