Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published: 2024-04-02T09:51:52.370Z

Updated: 2024-08-01T19:25:41.647Z

Reserved: 2024-03-20T14:46:17.613Z

Link: CVE-2024-2745

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:41.647Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-04-02T10:15:09.950

Modified: 2024-04-02T12:50:42.233

Link: CVE-2024-2745

cve-icon Redhat

No data.