Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-2745

Опубликовано: 02 апр. 2024
Источник: nvd
CVSS3: 3.3
EPSS Низкий

Описание

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*
Версия до 6.6.244 (исключая)

EPSS

Процентиль: 24%
0.0008
Низкий

3.3 Low

CVSS3

Дефекты

CWE-598
NVD-CWE-Other

Связанные уязвимости

CVSS3: 3.3
github
почти 2 года назад

Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

EPSS

Процентиль: 24%
0.0008
Низкий

3.3 Low

CVSS3

Дефекты

CWE-598
NVD-CWE-Other