#VU51578 Information disclosure in Nessus Agent - CVE-2021-20077
Published: March 19, 2021
Nessus Agent
Tenable Network Security
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to Nessus Agent inadvertently
captures the IAM role security token on the local host during initial
linking of the Nessus Agent when installed on an Amazon EC2 instance. A local privileged user can obtain the token.