Skip to content

Instantly share code, notes, and snippets.

@nyxfqq
Created July 31, 2024 03:16
Show Gist options
  • Save nyxfqq/c796ef4a0f3d93736c42022e085f78d7 to your computer and use it in GitHub Desktop.
Save nyxfqq/c796ef4a0f3d93736c42022e085f78d7 to your computer and use it in GitHub Desktop.
CVE-2024-41262
[Suggested description]
immudb v1.9.3 was discovered to use the HTTP protocol in the
ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing
attackers to intercept communications via a man-in-the-middle attack.
------------------------------------------
[VulnerabilityType Other]
CWE-319
------------------------------------------
[Vendor of Product]
https://github.com/codenotary/immudb
------------------------------------------
[Affected Product Code Base]
immudb - <=1.9.3
------------------------------------------
[Affected Component]
immudb cmd service
------------------------------------------
[Attack Type]
Remote
------------------------------------------
[Impact Information Disclosure]
true
------------------------------------------
[Attack Vectors]
use 'immuadmin stats' command
------------------------------------------
[Reference]
https://docs.immudb.io/
------------------------------------------
[Discoverer]
Yuexi Zhang
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment