CVE-2024-4220
Published Jun 4, 2024Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Vendor/product archive
2 CVEs tagged to beyondtrust / beyondinsight — 0 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Prior to 23.1, an information disclosure vulnerability exists within BeyondInsight which can allow an attacker to enumerate usernames.
Prior to 23.2, it is possible to perform arbitrary Server-Side requests via HTTP-based connectors within BeyondInsight, resulting in a server-side request forgery vulnerability.