In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-17328 In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.
Fixes

Solution

Update to at least version 0.42.0 of Rapid7 Komand


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-09-17T02:47:31.152Z

Reserved: 2018-01-12T00:00:00

Link: CVE-2018-5559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-28T19:29:00.243

Modified: 2024-11-21T04:09:03.857

Link: CVE-2018-5559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses