First published: Thu Mar 21 2024(Updated: )
An issue in iTop DualSafe Password Manager & Digital Vault before 1.4.24 allows a local attacker to obtain sensitive information via leaked credentials as plaintext in a log file that can be accessed by the local user without knowledge of the master secret.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
iTop DualSafe Password Manager & Digital Vault | <1.4.24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24272 is considered a medium severity vulnerability due to the potential exposure of sensitive information.
To fix CVE-2024-24272, upgrade iTop DualSafe Password Manager & Digital Vault to version 1.4.24 or later.
CVE-2024-24272 allows for the leakage of credentials in plaintext, which can lead to unauthorized access.
A local attacker with access to the system can exploit CVE-2024-24272 to obtain leaked credentials.
CVE-2024-24272 affects all versions of iTop DualSafe Password Manager & Digital Vault prior to 1.4.24.