CVE-2020-1987Low

CVE-2020-1987 GlobalProtect App: VPN cookie local information disclosure

Published
April 8, 2020
Last Modified
April 8, 2020

🔗 CVE IDs covered (1)

📋 Description

An information exposure vulnerability in the logging component of Palo Alto Networks GlobalProtect App allows a local authenticated user to read VPN cookie information when the troubleshooting logging level is set to "Dump". This issue affects Palo Alto Networks GlobalProtect App 5.0 versions prior to 5.0.9; 5.1 versions prior to 5.1.1.

🎯 Affected products1

  • GlobalProtect App

✅ Remediation

This issue is fixed in GlobalProtect App 5.0.9, GlobalProtect App 5.1.1 and all later versions.

🔗 References (1)