CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Asp | Centra | * | * |
Centraone | Centra | 5.2 (including) | 5.2 (including) |
Smart_connect | Centra | cen5.2-03 (including) | cen5.2-03 (including) |