MEDIUM
Sensitive information disclosure in KNIME Hub Web Application
Published Jun 7, 2023
5.3
MEDIUMCVSS 3.1
EPSS 0.64%
Description
The Web Frontend of KNIME Business Hub before 1.4.0 allows an unauthenticated remote attacker to access internals about the application such as versions, host names, or IP addresses. No personal information or application data was exposed.
Affected products
-
Affected
- ≥ 1.0.0, < 1.4.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Knime | KNIME Business Hub | unaffected | Affected
|
- < 1.4.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
An update to KNIME Business Hub 1.4.0 is advised.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34020 Advisory
- https://www.knime.com/security/advisories#CVE-2023-2541 Vendor Advisory
- https://zigrin.com/advisories/knime-business-hub-sensitive-information-disclosure/ Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-34020 | Advisory | |
| https://www.knime.com/security/advisories#CVE-2023-2541 | Vendor Advisory | |
| https://zigrin.com/advisories/knime-business-hub-sensitive-information-disclosure/ | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner KNIME
Published Jun 7, 2023
Updated Sep 4, 2024
Reserved May 5, 2023
Link CVE-2023-2541
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data