CVE-2024-2745

Published Apr 2, 2024

Last updated a month ago

Overview

Description
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 
Source
cve@rapid7.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
3.3
Impact score
1.4
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

Weaknesses

cve@rapid7.com
CWE-598
nvd@nist.gov
NVD-CWE-Other

Social media

Hype score
Not currently trending

Configurations