Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 28 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Strangebee
Strangebee thehive |
|
| CPEs | cpe:2.3:a:strangebee:thehive:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Strangebee
Strangebee thehive |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thehive-project
Thehive-project thehive |
|
| Vendors & Products |
Thehive-project
Thehive-project thehive |
Fri, 17 Jul 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials. | |
| Title | TheHive 4.1.24 Unauthenticated Information Disclosure via /api/status Endpoint | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-28T01:50:01.477Z
Reserved: 2026-07-15T15:45:44.601Z
Link: CVE-2026-63098
Updated: 2026-07-17T17:26:49.767Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-27T23:15:13Z