SB2021040621 - Information disclosure in Nessus
Published: April 6, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Information disclosure (CVE-ID: CVE-2021-20077)
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Nessus Agent inadvertently
captures the IAM role security token on the local host during initial
linking of the Nessus Agent when installed on an Amazon EC2 instance. A local privileged user can obtain the token.
Remediation
Install update from vendor's website.