Vulnerability Description
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc. The vulnerability is remediated in version 6.6.244.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Insightvm | < 6.6.244 |
Related Weaknesses (CWE)
References
- https://docs.rapid7.com/release-notes/insightvm/20240327/Release Notes
- https://docs.rapid7.com/release-notes/insightvm/20240327/Release Notes
FAQ
What is CVE-2024-2745?
CVE-2024-2745 is a vulnerability with a CVSS score of 3.3 (LOW). Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is atte...
How severe is CVE-2024-2745?
CVE-2024-2745 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2745?
Check the references section above for vendor advisories and patch information. Affected products include: Rapid7 Insightvm.