Description
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.
The vulnerability is remediated in version 6.6.244.
The vulnerability is remediated in version 6.6.244.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27690 | Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc. The vulnerability is remediated in version 6.6.244. |
References
| Link | Providers |
|---|---|
| https://docs.rapid7.com/release-notes/insightvm/20240327/ |
|
History
Tue, 25 Feb 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rapid7
Rapid7 insightvm |
|
| Weaknesses | NVD-CWE-Other | |
| CPEs | cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rapid7
Rapid7 insightvm |
Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-08-01T19:25:41.647Z
Reserved: 2024-03-20T14:46:17.613Z
Link: CVE-2024-2745
Updated: 2024-08-01T19:25:41.647Z
Status : Analyzed
Published: 2024-04-02T10:15:09.950
Modified: 2025-02-25T18:36:41.020
Link: CVE-2024-2745
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD