Description
In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.
Published: 2018-11-28
Score: 3.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to at least version 0.42.0 of Rapid7 Komand

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2018-17328 In Rapid7 Komand version 0.41.0 and prior, certain endpoints that are able to list the always encrypted-at-rest connection data could return some configurations of connection data without obscuring sensitive data from the API response sent over an encrypted channel. This issue does not affect Rapid7 Komand version 0.42.0 and later versions.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-09-17T02:47:31.152Z

Reserved: 2018-01-12T00:00:00.000Z

Link: CVE-2018-5559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-28T19:29:00.243

Modified: 2026-06-17T02:00:31.357

Link: CVE-2018-5559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-212

    Improper Removal of Sensitive Information Before Storage or Transfer

  • CWE-312

    Cleartext Storage of Sensitive Information