CVE-2024-2745
Rapid7 InsightVM Sensitive Information Exposure via URL
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.3EPSS 0.2%KEV nãoPoC —Patch —
Ciclo de vida
02 abr 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.
The vulnerability is remediated in version 6.6.244.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Produtos afetados
Rapid7 · InsightVMQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →