CVE-2024-41262

mmudb v1.9.3 was discovered to use the HTTP protocol in the ShowMetricsRaw and ShowMetricsAsText functions, possibly allowing attackers to intercept communications via a man-in-the-middle attack.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:codenotary:immudb:1.9.3:*:*:*:*:*:*:*

History

10 Jul 2025, 15:56

Type Values Removed Values Added
CPE cpe:2.3:a:codenotary:immudb:1.9.3:*:*:*:*:*:*:*
References () https://gist.github.com/nyxfqq/c796ef4a0f3d93736c42022e085f78d7 - () https://gist.github.com/nyxfqq/c796ef4a0f3d93736c42022e085f78d7 - Third Party Advisory
First Time Codenotary immudb
Codenotary

01 Aug 2024, 16:35

Type Values Removed Values Added
CWE CWE-319
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.4

01 Aug 2024, 12:42

Type Values Removed Values Added
Summary
  • (es) Se descubrió que mmudb v1.9.3 utiliza el protocolo HTTP en las funciones ShowMetricsRaw y ShowMetricsAsText, lo que posiblemente permite a los atacantes interceptar las comunicaciones a través de un ataque de man-in-the-middle.

31 Jul 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-31 22:15

Updated : 2025-07-10 15:56


NVD link : CVE-2024-41262

Mitre link : CVE-2024-41262

CVE.ORG link : CVE-2024-41262


JSON object : View

Products Affected

codenotary

  • immudb
CWE
CWE-319

Cleartext Transmission of Sensitive Information