CVE Vulnerabilities

CVE-2024-2745

Use of GET Request Method With Sensitive Query Strings

Published: Apr 02, 2024 | Modified: Apr 02, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Rapid7s InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded.  This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.     The vulnerability is remediated in version 6.6.244. 

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Potential Mitigations

References