CVE-2022-29550
Published on: Not Yet Published
Last Modified on: 09/15/2022 04:48:00 PM UTC
Certain versions of Cloud Agent from Qualys contain the following vulnerability:
** DISPUTED ** An issue was discovered in Qualys Cloud Agent 4.8.0-49. It writes "ps auxwwe" output to the /var/log/qualys/qualys-cloud-agent-scan.log file. This may, for example, unexpectedly write credentials (from environment variables) to disk in cleartext. NOTE: there are no common circumstances in which qualys-cloud-agent-scan.log can be read by a user other than root; however, the file contents could be exposed through site-specific operational practices. The vendor does NOT characterize this as a vulnerability because the ps data collection is intentional, and would only capture credentials on a machine that was already affected by the CWE-214 weakness.
- CVE-2022-29550 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
CVSS3 Score: 5.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Full Disclosure: Multiple vulnerabilities discovered in Qualys Cloud Agent | seclists.org text/html |
![]() |
Category: Vulnerabilities and Threat Research | Qualys Security Blog | blog.qualys.com text/html |
![]() |
Qualys Cloud Agent Arbitrary Code Execution ≈ Packet Storm | packetstormsecurity.com text/html |
![]() |
Qualys Security Updates: Cloud Agent for Linux | Qualys Security Blog | blog.qualys.com text/html |
![]() |
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Qualys | Cloud Agent | 4.8.0-49 | All | All | All |
- cpe:2.3:a:qualys:cloud_agent:4.8.0-49:*:*:*:*:linux:*:*:
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-29550 | 2022-08-18 14:38:51 |