Description
CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.
Affected products
- centra / asp
- centra / centraone5.2 – 5.2
- centra / smart_connectcen5.2-03 – cen5.2-03