Vulnerability CVE-2021-31797


Published: 2021-09-02

Description:
The user identification mechanism used by CyberArk Credential Provider prior to 12.1 is susceptible to a local host race condition, leading to password disclosure.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
CyberArk Credential Provider Race Condition / Authorization Bypass
Klayton Monroe
04.09.2021

 References:
https://www.cyberark.com/resources/blog
https://korelogic.com/Resources/Advisories/KL-001-2021-009.txt
http://seclists.org/fulldisclosure/2021/Sep/2

Copyright 2024, cxsecurity.com

 

Back to Top