CVE-2024-9798

The health endpoint is public so everybody can see a list of all services. It is potentially valuable information for attackers.
References
Link Resource
https://github.com/zowe/api-layer Product
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*
cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*

History

19 Dec 2024, 17:00

Type Values Removed Values Added
First Time Linuxfoundation zowe Api Mediation Layer
CPE cpe:2.3:a:linuxfoundation:api_mediation_layer:*:*:*:*:*:*:*:* cpe:2.3:a:linuxfoundation:zowe_api_mediation_layer:*:*:*:*:*:*:*:*

Information

Published : 2024-10-10 08:15

Updated : 2024-12-19 17:00


NVD link : CVE-2024-9798

Mitre link : CVE-2024-9798

CVE.ORG link : CVE-2024-9798


JSON object : View

Products Affected

linuxfoundation

  • zowe_api_mediation_layer
CWE
CWE-312

Cleartext Storage of Sensitive Information