Rapid7's InsightVM maintenance mode login page suffers...
Low severity
Unreviewed
Published
Apr 2, 2024
to the GitHub Advisory Database
•
Updated Apr 2, 2024
Description
Published by the National Vulnerability Database
Apr 2, 2024
Published to the GitHub Advisory Database
Apr 2, 2024
Last updated
Apr 2, 2024
Rapid7's InsightVM maintenance mode login page suffers from a sensitive information exposure vulnerability whereby, sensitive information is exposed through query strings in the URL when login is attempted before the page is fully loaded. This vulnerability allows attackers to acquire sensitive information such as passwords, auth tokens, usernames etc.
The vulnerability is remediated in version 6.6.244.
References