Description
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.  
 
The vulnerability is remediated in version 6.6.244. 

Published: 2024-04-02
Score: 3.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-27690 Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 
History

Tue, 25 Feb 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Rapid7
Rapid7 insightvm
Weaknesses NVD-CWE-Other
CPEs cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*
Vendors & Products Rapid7
Rapid7 insightvm

Subscriptions

Rapid7 Insightvm
cve-icon MITRE

Status: PUBLISHED

Assigner: rapid7

Published:

Updated: 2024-08-01T19:25:41.647Z

Reserved: 2024-03-20T14:46:17.613Z

Link: CVE-2024-2745

cve-icon Vulnrichment

Updated: 2024-08-01T19:25:41.647Z

cve-icon NVD

Status : Analyzed

Published: 2024-04-02T10:15:09.950

Modified: 2025-02-25T18:36:41.020

Link: CVE-2024-2745

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses