Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6861

Опубликовано: 06 нояб. 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 7.5
redhat
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

CVSS3: 7.5
debian
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via th ...

CVSS3: 7.5
github
около 1 года назад

A disclosure of sensitive information flaw was found in foreman via the GraphQL API. If the introspection feature is enabled, it is possible for attackers to retrieve sensitive admin authentication keys which could result in a compromise of the entire product's API.

EPSS

Процентиль: 52%
0.00292
Низкий

7.5 High

CVSS3

Дефекты

CWE-200