Description
The StrongDM Client insufficiently protected a pre-authentication token. Attackers could exploit this to intercept and reuse the token, potentially redeeming valid authentication credentials through a race condition.
Problem types
CWE-319 Cleartext Transmission of Sensitive Information
Product status
Any version
References
security.strongdm.com/...6fde839-9388-4361-8d3b-9baa7b2de2ed