NVIDIA Omniverse Workstation Launcher for Windows and Linux contains a vulnerability in the authentication flow, where a user’s access token is displayed in the browser user's address bar. An attacker could use this token to impersonate the user to access launcher resources. A successful exploit of this vulnerability may lead to information disclosure.
The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.
Link | Tags |
---|---|
https://nvidia.custhelp.com/app/answers/detail/a_id/5472 | vendor advisory |