PT-2026-3557 · Unknown · Verve Asset Manager
CVE-2025-14377
·
Publicado
2026-01-20
·
Atualizado
2026-01-20
CVSS v4.0
8.8
Alta
| Vetor | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Verve Asset Manager versions prior to 1.36
Description
A security issue exists in the legacy Ansible playbook component of Verve Asset Manager. The issue involves the incorrect storage of plaintext secrets during playbook execution. The affected component has been retired and is optional since the 1.36 release.
Recommendations
Update to version 1.36 or later.
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Verve Asset Manager