In Stormshield SSO Agent 2.x before 2.1.1 and 3.x before 3.0.2, the cleartext user password and PSK are contained in the log file of the .exe installer.
References
Link Resource
https://advisories.stormshield.eu/2022-001 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-01-17T20:04:02

Updated: 2022-01-17T20:04:02

Reserved: 2022-01-06T00:00:00


Link: CVE-2022-22703

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-01-17T21:15:07.663

Modified: 2022-01-24T19:17:58.217


Link: CVE-2022-22703

JSON object: View

cve-icon Redhat Information

No data.

CWE