Vulnerabilities
Vulnerable Software
Strangebee:  >> Thehive  >> 2.13.4  Security Vulnerabilities
TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by sending a GET request to the /api/status endpoint, which lacks authentication enforcement in the StatusCtrl.scala handler. Attackers can obtain the datastore attachment protection password, configured authentication providers, SSO settings, MFA capabilities, and clustered node addresses and roles without any credentials.
CVSS Score
6.9
EPSS Score
0.003
Published
2026-07-17
An issue in StrangeBee TheHive v.5.0.8, v.4.1.21 and Cortex v.3.1.6 allows a remote attacker to gain privileges via Active Directory authentication mechanism.
CVSS Score
9.8
EPSS Score
0.007
Published
2023-09-11


Contact Us

Shodan ® - All rights reserved