CentraOne 5.2 and Centra ASP with basic authentication enabled creates world-writable base64 encoded log files, which allows local users to obtain cleartext passwords from decoded log files and impersonate users.
| Software | From | Fixed in |
|---|---|---|
| centra / centraone | 5.2 | 5.2.x |
| centra / smart_connect | cen5.2-03 | cen5.2-03.x |
| centra / asp | - | - |