An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the Admin Framework component. It allows local users to discover a password by listing a process and its arguments during sysadminctl execution.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Mac_os_x | Apple | * | 10.13.4 (excluding) |