Encrypted User Credentials Exposed in Application Logs
CVE-2024-5908
Key Information:
- Vendor
Palo Alto Networks
- Status
- Vendor
- CVE Published:
- 12 June 2024
Badges
What is CVE-2024-5908?
A security concern has been identified within the Palo Alto Networks GlobalProtect application. This issue allows for the exposure of encrypted user credentials within application logs that, while generally accessible only to local users, can compromise sensitive information when logs are shared for troubleshooting. Such logs can potentially be viewed by unintended recipients, posing risks to user privacy and data security. It is crucial for organizations using the GlobalProtect application to implement recommended measures to mitigate exposure and protect sensitive user credentials.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GlobalProtect App 5.1.0 < 5.1.12
GlobalProtect App 6.0.0 < 6.0.8
GlobalProtect App 6.1.0 < 6.1.3
References
CVSS V3.1
Timeline
- ๐พ
Exploit known to exist
Vulnerability published