Thehive-project

Thehive

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 17.07.2026 15:39:44
  • Zuletzt bearbeitet 17.07.2026 18:04:04

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated user to access attachments belonging to other organizations by supplying a content-hash identifier. A...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 17.07.2026 15:38:08
  • Zuletzt bearbeitet 30.07.2026 14:25:41

TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication en...