A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the –show-inputs-only flag.
The product stores sensitive information without properly limiting read or write access by unauthorized actors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Zowe_cli | Zowe | * | * |