CVE-2024-1098: Rebuild proxy-download QiniuCloud.getStorageFile information disclosure
A vulnerability was found in Rebuild up to 3.5.5 and classified as problematic. This issue affects the function QiniuCloud.getStorageFile of the file /filex/proxy-download. The manipulation of the argument url leads to information disclosure. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252455.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1098?
CVE-2024-1098 is classified as a problematic vulnerability affecting Rebuild versions up to 3.5.5.
How do I fix CVE-2024-1098?
To fix CVE-2024-1098, upgrade to a version of Rebuild that is beyond 3.5.5.
What type of vulnerability is CVE-2024-1098?
CVE-2024-1098 is an information disclosure vulnerability caused by improper handling of the URL argument.
Which software is affected by CVE-2024-1098?
CVE-2024-1098 affects Rebuild, specifically versions up to and including 3.5.5.
What can attackers gain from exploiting CVE-2024-1098?
Exploiting CVE-2024-1098 can allow attackers to disclose sensitive information via the getStorageFile function.