Attackers Can Discover User Credentials via /api/resources Endpoint in Affected Versions of Retool
CVE-2024-42056

6.5MEDIUM

Key Information:

Vendor

Retool

Status
Vendor
CVE Published:
22 August 2024

What is CVE-2024-42056?

Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.