CVE-2024-33865: Infoleak
Published May 14, 2024
·Updated
An issue was discovered in linqi before 1.4.0.1 on Windows. There is an NTLM hash leak via the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID] endpoints.
Affected Software
3 affected components
linqi linqi<1.4.0.1
All of the following
linqi linqi<1.4.0.1
Microsoft Windows
Event History
Jan 1, 1970
CVE Published
via MITRE·12:00 AM
May 14, 2024
CVE Published
via NVD·04:17 PM
Sep 4, 2024
Data Sourced
via MITRE·08:19 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-33865?
CVE-2024-33865 has been classified with a medium severity due to the potential for NTLM hash leaks.
2
How do I fix CVE-2024-33865?
To mitigate CVE-2024-33865, upgrade to linqi version 1.4.0.1 or later.
3
What specific endpoints are affected by CVE-2024-33865?
CVE-2024-33865 affects the /api/Cdn/GetFile and /api/DocumentTemplate/{GUID} endpoints.
4
What kind of data is leaked in CVE-2024-33865?
CVE-2024-33865 results in the leaking of NTLM hashes.
5
Which versions of linqi are affected by CVE-2024-33865?
CVE-2024-33865 affects all versions of linqi prior to 1.4.0.1.