CVE Vulnerabilities

CVE-2024-41260

Use of Hard-coded Cryptographic Key

Published: Aug 01, 2024 | Modified: Dec 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A static initialization vector (IV) in the encrypt function of netbird managements service from v0.23.2 to v0.29.1 allows attackers to obtain sensitive information (email addresses) when in possession of the audit events database.

Weakness

The product uses a hard-coded, unchangeable cryptographic key.

Potential Mitigations

References