Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4xh-mr6x-3f7c

Опубликовано: 02 апр. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3.3

Описание

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

EPSS

Процентиль: 24%
0.0008
Низкий

3.3 Low

CVSS3

Дефекты

CWE-598

Связанные уязвимости

CVSS3: 3.3
nvd
почти 2 года назад

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

EPSS

Процентиль: 24%
0.0008
Низкий

3.3 Low

CVSS3

Дефекты

CWE-598