CVE-2024-10965

A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named c9ce39747e0372aaa2157b2b56174914a12c06d8. It is recommended to apply a patch to fix this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:emqx:neuron:*:*:*:*:*:*:*:*

History

23 Nov 2024, 01:45

Type Values Removed Values Added
First Time Emqx neuron
Emqx
CPE cpe:2.3:a:emqx:neuron:*:*:*:*:*:*:*:*
CWE NVD-CWE-noinfo
References () https://github.com/emqx/neuron/issues/2281 - () https://github.com/emqx/neuron/issues/2281 - Exploit, Issue Tracking, Third Party Advisory
References () https://github.com/emqx/neuron/pull/2282 - () https://github.com/emqx/neuron/pull/2282 - Issue Tracking, Patch
References () https://github.com/fengzeroz/neuron/commit/c9ce39747e0372aaa2157b2b56174914a12c06d8 - () https://github.com/fengzeroz/neuron/commit/c9ce39747e0372aaa2157b2b56174914a12c06d8 - Patch
References () https://vuldb.com/?ctiid.283411 - () https://vuldb.com/?ctiid.283411 - Permissions Required
References () https://vuldb.com/?id.283411 - () https://vuldb.com/?id.283411 - Third Party Advisory
References () https://vuldb.com/?submit.435375 - () https://vuldb.com/?submit.435375 - Third Party Advisory

08 Nov 2024, 19:01

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como problemática en emqx neuron hasta la versión 2.10.0. Esta vulnerabilidad afecta a una funcionalidad desconocida del archivo /api/v2/schema del componente JSON File Handler. La manipulación conduce a la divulgación de información. El ataque se puede lanzar de forma remota. El parche se llama c9ce39747e0372aaa2157b2b56174914a12c06d8. Se recomienda aplicar un parche para solucionar este problema.

07 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-07 17:15

Updated : 2024-11-23 01:45


NVD link : CVE-2024-10965

Mitre link : CVE-2024-10965

CVE.ORG link : CVE-2024-10965


JSON object : View

Products Affected

emqx

  • neuron
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-284

Improper Access Control

NVD-CWE-noinfo