PT-2024-21905 · Rapid7 · Rapid7 Insightvm
Sreenath Raghunath
·
Published
2024-04-02
·
Updated
2025-02-25
·
CVE-2024-2745
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 InsightVM versions prior to 6.6.244
Description
The maintenance mode login page of Rapid7 InsightVM suffers from a sensitive information exposure issue, where sensitive information such as passwords, auth tokens, and usernames are exposed through query strings in the URL when a login attempt is made before the page is fully loaded. This allows attackers to acquire sensitive information.
Recommendations
For versions prior to 6.6.244, update to version 6.6.244 or later to remediate the vulnerability. As a temporary workaround, consider avoiding login attempts before the page is fully loaded to minimize the risk of sensitive information exposure. Restrict access to the maintenance mode login page until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Insightvm