Логотип exploitDog
bind:CVE-2024-42056
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-42056

Количество 2

Количество 2

nvd логотип

CVE-2024-42056

больше 1 года назад

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f3c7-2m22-wr7x

больше 1 года назад

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-42056

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-f3c7-2m22-wr7x

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

CVSS3: 6.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу