Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.
The vulnerability is remediated in version 6.6.244.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://docs.rapid7.com/release-notes/insightvm/20240327/ |
![]() ![]() ![]() |
History
Tue, 25 Feb 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rapid7
Rapid7 insightvm |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:* | |
Vendors & Products |
Rapid7
Rapid7 insightvm |

Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2024-08-01T19:25:41.647Z
Reserved: 2024-03-20T14:46:17.613Z
Link: CVE-2024-2745

Updated: 2024-08-01T19:25:41.647Z

Status : Analyzed
Published: 2024-04-02T10:15:09.950
Modified: 2025-02-25T18:36:41.020
Link: CVE-2024-2745

No data.