IRIS is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 return sensitive data to the user which are not required for the client’s operation. Version 2.4.28 contains a patch.
References
Configurations
No configuration.
History
08 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/dfir-iris/iris-web/security/advisories/GHSA-g588-5gmf-p5cx - |
04 Jun 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-04 22:16
Updated : 2026-06-08 17:16
NVD link : CVE-2026-42539
Mitre link : CVE-2026-42539
CVE.ORG link : CVE-2026-42539
JSON object : View
Products Affected
No product.
CWE
CWE-201
Insertion of Sensitive Information Into Sent Data
