Cleartext Password Vulnerability in Stormshield SSO Agent by Stormshield
CVE-2022-22703
5.5MEDIUM
What is CVE-2022-22703?
The Stormshield SSO Agent versions 2.x prior to 2.1.1 and 3.x prior to 3.0.2 contain a security flaw where user passwords and Pre-Shared Keys (PSKs) are logged in cleartext within the installation log file. This exposure poses a significant risk, as unauthorized individuals gaining access to these logs can easily retrieve sensitive credentials, potentially leading to unauthorized access and compromise of systems relying on this authentication method.
