Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2024-5813

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A medium severity vulnerability in BIPS has been identified where an authenticated attacker with high privileges can access the SSH private keys via an information leak in the server response.
Attacker Value
Unknown

CVE-2024-5812

Disclosure Date: June 11, 2024 (last updated February 12, 2025)
A low severity vulnerability in BIPS has been identified where an attacker with high privileges or a compromised high privilege account can overwrite Read-Only smart rules via a specially crafted API request.
Attacker Value
Unknown

CVE-2024-4220

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Attacker Value
Unknown

CVE-2024-4219

Disclosure Date: June 04, 2024 (last updated June 12, 2024)
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.