CyberRota Analysis
AI-GeneratedTheHive versions up to 4.1.24 are vulnerable to an unauthenticated information disclosure flaw that allows attackers to access sensitive configuration data via the /api/status endpoint. This vulnerability can expose critical information such as datastore passwords, authentication provider configurations, and SSO settings. Organizations using TheHive should prioritize patching this issue to protect against potential unauthorized access and data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.
Related CVEs
Other vulnerabilities affecting the same vendor(s)