CVE Vulnerabilities

CVE-2024-32931

Use of GET Request Method With Sensitive Query Strings

Published: Aug 01, 2024 | Modified: Aug 09, 2024
CVSS 3.x
5.7
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

Weakness

The web application uses the HTTP GET method to process a request and includes sensitive information in the query string of that request.

Affected Software

NameVendorStart VersionEnd Version
Exacqvision_web_serviceJohnsoncontrols*24.03 (including)

Potential Mitigations

References