CVE-2024-12564: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ODA CDE inWEB SDK before 2025.3
Exposure of Sensitive Information to an Unauthorized Actor vulnerability was discovered in Open Design Alliance CDE inWEB SDK before 2025.3. Installing CDE Server with default settings allows unauthorized users to visit prometheus metrics page. This can allow attackers to understand more things about the target application which may help in further investigation and exploitation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12564?
CVE-2024-12564 is classified as a medium severity vulnerability due to its potential exposure of sensitive information.
How do I fix CVE-2024-12564?
To address CVE-2024-12564, you should reconfigure the CDE Server settings to restrict access to the Prometheus metrics page.
What kind of information is exposed in CVE-2024-12564?
CVE-2024-12564 potentially exposes sensitive metrics that can be leveraged by unauthorized users to understand system performance and behavior.
Which versions are affected by CVE-2024-12564?
CVE-2024-12564 affects the Open Design Alliance CDE inWEB SDK versions prior to 2025.3.
Who is the vendor for CVE-2024-12564?
The vendor for CVE-2024-12564 is Open Design Alliance.