In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: rapid7
Published: 2018-11-28T19:00:00Z
Updated: 2024-09-17T02:47:31.152Z
Reserved: 2018-01-12T00:00:00
Link: CVE-2018-5559
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-11-28T19:29:00.243
Modified: 2024-11-21T04:09:03.857
Link: CVE-2018-5559
Redhat
No data.