Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-28251

Опубликовано: 14 мар. 2024
Источник: nvd
CVSS3: 5.6
CVSS3: 7.3
EPSS Низкий

Описание

Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading any cells as well as for watching the live status of query executions. Currently the CORS setting allows all origins, which could result in cross-site websocket hijacking and allow attackers to read/edit/remove datadocs of the user. This issue has been addressed in version 3.32.0. Users are advised to upgrade. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pinterest:querybook:*:*:*:*:*:*:*:*
Версия до 3.32.0 (исключая)

EPSS

Процентиль: 39%
0.00177
Низкий

5.6 Medium

CVSS3

7.3 High

CVSS3

Дефекты

CWE-345

EPSS

Процентиль: 39%
0.00177
Низкий

5.6 Medium

CVSS3

7.3 High

CVSS3

Дефекты

CWE-345