Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 
History

Tue, 25 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Rapid7
Rapid7 insightvm
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*
Vendors & Products Rapid7
Rapid7 insightvm

cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-08-01T19:25:41.647Z

Reserved: 2024-03-20T14:46:17.613Z

Link: CVE-2024-2745

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:41.647Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-02T10:15:09.950

Modified: 2025-02-25T18:36:41.020

Link: CVE-2024-2745

cve-icon Redhat

No data.