Vulnerabilities
Vulnerable Software
Strangebee:  >> Thehive  >> 2.13.1  Security Vulnerabilities
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-07-17
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-09-11
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's privileges. This affects app/controllers/UserCtrl.scala.
CVSS Score
8.8
EPSS Score
0.019
Published
2019-06-02


Contact Us

Shodan ® - All rights reserved