CVE-2019-0021

On Juniper ATP, secret passphrase CLI inputs, such as "set mcm", are logged to /var/log/syslog in clear text, allowing authenticated local user to be able to view these secret information. This issue affects Juniper ATP 5.0 versions prior to 5.0.4.
References
Link Resource
https://kb.juniper.net/JSA10918 Vendor Advisory
Configurations

Configuration 1


Information

Published : 2019-01-15 09:29

Updated : 2019-10-09 11:43


NVD link : CVE-2019-0021

Mitre link : CVE-2019-0021

Products Affected
CWE
CWE-532

Insertion of Sensitive Information into Log File