PT-2026-3557 · Unknown · Verve Asset Manager

CVE-2025-14377

·

Publicado

2026-01-20

·

Atualizado

2026-01-20

CVSS v4.0

8.8

Alta

VetorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Verve Asset Manager versions prior to 1.36
Description A security issue exists in the legacy Ansible playbook component of Verve Asset Manager. The issue involves the incorrect storage of plaintext secrets during playbook execution. The affected component has been retired and is optional since the 1.36 release.
Recommendations Update to version 1.36 or later.

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-14377

Produtos afetados

Verve Asset Manager