#VU70079 Inclusion of Sensitive Information in Log Files in vCenter Server - CVE-2022-31697
Published: December 9, 2022
vCenter Server
VMware, Inc
Description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to software stores credentials in plain text into log files. A local user with access to a workstation that invoked a vCenter Server Appliance ISO operation (Install/Upgrade/Migrate/Restore) can access plaintext passwords used during that operation.