Lucene search

K
nvd551230f0-3615-47bd-b7cc-93e92e730bbfNVD:CVE-2023-49113
HistoryJun 20, 2024 - 1:15 p.m.

CVE-2023-49113

2024-06-2013:15:49
CWE-312
551230f0-3615-47bd-b7cc-93e92e730bbf
web.nvd.nist.gov
2
kiuwan local analyzer
java scanning application
hard-coded secrets
plain text format
confidentiality compromise
jar files
insightservicesconfig.properties
insight.github.user
insight.github.password
github account
encryptor.properties
encryption key
kiuwan sast

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.0%

The Kiuwan Local Analyzer (KLA) Java scanning application contains several
hard-coded secrets in plain text format. In some cases, this can
potentially compromise the confidentiality of the scan results.Β Several credentials were found in the JAR files of the Kiuwan Local Analyzer.

The
JAR file β€œlib.engine/insight/optimyth-insight.jar” contains the file
β€œInsightServicesConfig.properties”, which has the configuration tokens
β€œinsight.github.user” as well as β€œinsight.github.password” prefilled
with credentials. At least the specified username corresponds to a valid
GitHub account.Β The
JAR file β€œlib.engine/insight/optimyth-insight.jar” also contains the
file β€œes/als/security/Encryptor.properties”, in which the key used for
encrypting the results of any performed scan.

This issue affects Kiuwan SAST: <master.1808.p685.q13371

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.0004 Low

EPSS

Percentile

9.0%

Related for NVD:CVE-2023-49113