An issue was discovered in WeCube Platform 3.2.2. Cleartext passwords are displayed in the configuration for terminal plugins.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Link | Tags |
---|---|
https://github.com/WeBankPartners/wecube-plugins-terminal | third party advisory |
https://github.com/WeBankPartners/wecube-platform/issues/2329 | third party advisory exploit |