Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Knightliao

#39612of 53,624
6.9Total CVSS
Vulnerabilities · 1
PT-2024-16416
6.9
2024-10-31
Knightliao · Disconf · CVE-2024-10620
**Name of the Vulnerable Software and Affected Versions** knightliao Disconf version 2.6.36 **Description** A critical issue has been found, affecting an unknown part of the file `/api/config/list` of the component Configuration Center. This leads to improper authentication and can be initiated remotely. The exploit has been disclosed to the public and may be used. **Recommendations** For version 2.6.36, consider disabling access to the `/api/config/list` endpoint until a patch is available. Restrict access to the Configuration Center component to minimize the risk of exploitation. Avoid using this version until a fixed version is released. At the moment, there is no information about a newer version that contains a fix for this issue.