A problem with the Palo Alto Networks GlobalProtect app can result in exposure of encrypted user credentials, used for connecting to GlobalProtect, in application logs. Normally, these application logs are only viewable by local users and are included when generating logs for troubleshooting purposes. This means that these encrypted credentials are exposed to recipients of the application logs.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://security.paloaltonetworks.com/CVE-2024-5908 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: palo_alto
Published: 2024-06-12T16:28:08.131Z
Updated: 2024-06-12T16:28:08.131Z
Reserved: 2024-06-12T15:27:55.490Z
Link: CVE-2024-5908
JSON object: View
NVD Information
Status : Awaiting Analysis
Published: 2024-06-12T17:15:53.253
Modified: 2024-06-13T18:36:09.010
Link: CVE-2024-5908
JSON object: View
Redhat Information
No data.
CWE