CVE Vulnerabilities

CVE-2024-45787

Published: Sep 11, 2024 | Modified: Sep 18, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

This vulnerability exists in Reedos aiM-Star version 2.0.1 due to transmission of sensitive information in plain text in certain API endpoints. An authenticated remote attacker could exploit this vulnerability by manipulating a parameter through API request URL and intercepting response of the API request leading to exposure of sensitive information belonging to other users.

Affected Software

Name Vendor Start Version End Version
Aim-star Reedos 2.0.1 (including) 2.0.1 (including)

References