PT-2018-17047 · Rapid7 · Rapid7 Komand
Alex
+1
·
Publicado
2018-11-28
·
Atualizado
2019-10-09
·
CVE-2018-5559
CVSS v3.1
4.9
Média
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Komand versions prior to 0.42.0
Description
The issue concerns certain endpoints that can list always encrypted-at-rest connection data, potentially returning configurations without obscuring sensitive data in the API response.
Recommendations
For versions prior to 0.42.0, update to version 0.42.0 or later to resolve the issue.
Exploit
Correção
Cleartext Storage of Sensitive Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Rapid7 Komand