CVE Vulnerabilities

CVE-2023-32283

Insertion of Sensitive Information into Log File

Published: Nov 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insertion of sensitive information into log file in some Intel(R) On Demand software before versions 1.16.2, 2.1.1, 3.1.0 may allow an authenticated user to potentially enable information disclosure via local access.

Weakness

The product writes sensitive information to a log file.

Affected Software

Name Vendor Start Version End Version
On_demand Intel 1.16.1.1 (including) 1.16.1.1 (including)
On_demand Intel 2.1.0.1 (including) 2.1.0.1 (including)
On_demand Intel 3.0.1.3 (including) 3.0.1.3 (including)

Potential Mitigations

References