CVE-2024-6916: Zowe CLI --show-inputs-only displays securely stored properties
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Zowe CLIto a version that resolves this vulnerability.Fixed in 5.22.6 - Upgrade
Upgrade
Zowe CLIto a version that resolves this vulnerability.Fixed in 7.23.8 - Upgrade
Upgrade
Zoweto a version that resolves this vulnerability.Fixed in 2.16.0
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6916?
CVE-2024-6916 is considered a medium severity vulnerability as it allows local, privileged users to expose sensitive information.
How do I fix CVE-2024-6916?
To mitigate CVE-2024-6916, avoid using the '--show-inputs-only' flag in Zowe CLI until an update is applied.
Who is affected by CVE-2024-6916?
CVE-2024-6916 affects users of Zowe CLI, specifically those with local, privileged access.
What type of data is exposed in CVE-2024-6916?
CVE-2024-6916 exposes securely stored properties in cleartext, which can lead to unauthorized information disclosure.
Is there an immediate workaround for CVE-2024-6916?
An immediate workaround for CVE-2024-6916 is to refrain from executing commands that include the '--show-inputs-only' flag.