PT-2018-17047 · Rapid7 · Rapid7 Komand
Alex
+1
·
Published
2018-11-28
·
Updated
2019-10-09
·
CVE-2018-5559
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Komand versions prior to 0.42.0
Description
The issue concerns certain endpoints that can list always encrypted-at-rest connection data, potentially returning configurations without obscuring sensitive data in the API response.
Recommendations
For versions prior to 0.42.0, update to version 0.42.0 or later to resolve the issue.
Exploit
Fix
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rapid7 Komand