CVE Vulnerabilities

CVE-2024-55931

Insecure Storage of Sensitive Information

Published: Jan 27, 2025 | Modified: Jan 30, 2026
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Xerox Workplace Suite stores tokens in session storage, which may expose them to potential access if a users session is compromised. 

The patch for this vulnerability will be included in a future release of Workplace Suite, and customers will be notified through an update to the security bulletin.

Weakness

The product stores sensitive information without properly limiting read or write access by unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Workplace_suiteXerox*5.6.701.9 (excluding)

References