Intel

AIKIDO-2025-10629

@zowe/secrets-for-zowe-sdk is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

10

Low Risk

This Affects:

JS@zowe/secrets-for-zowe-sdk
8.0.0 - 8.26.2
Fixed in 8.27.0

TL;DR

Affected versions of this package are vulnerable to Information Exposure through logging. When the log level is set to TRACE for debugging purposes, the extension may inadvertently log Base64-encoded credentials. Although this behavior is documented as a warning, it presents an unexpected risk where sensitive authentication details are written to log files. An attacker with read access to these application log files could easily retrieve and decode the Base64 strings to obtain the cleartext credentials, potentially leading to unauthorized system access.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@zowe/secrets-for-zowe-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 8.0.0 - 8.26.2.

How to fix this

Upgrade the @zowe/secrets-for-zowe-sdk library to the patch version.