BeyondInsight
by Etrust
CVEs (2)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-4219 | Med | 0.31 | 4.8 | 0.00 | Jun 4, 2024 | Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability. | ||
| CVE-2024-4220 | Med | 0.28 | 4.3 | 0.00 | Jun 4, 2024 | Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames. |
- risk 0.31cvss 4.8epss 0.00
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.
- risk 0.28cvss 4.3epss 0.00
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.