CVE-2024-10620

Source
https://cve.org/CVERecord?id=CVE-2024-10620
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10620.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-10620
Published
2024-11-01T04:31:03.775Z
Modified
2026-07-15T01:49:19.599586298Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
knightliao Disconf Configuration Center list improper authentication
Details

A vulnerability was found in knightliao Disconf 2.6.36. It has been classified as critical. This affects an unknown part of the file /api/config/list of the component Configuration Center. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Database specific
{
    "cwe_ids": [
        "CWE-287"
    ],
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/10xxx/CVE-2024-10620.json"
}
References

Affected packages

Git / github.com/knightliao/disconf

Affected ranges

Type
GIT
Repo
https://github.com/knightliao/disconf
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "2.6.36"
        },
        {
            "last_affected": "2.6.36"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.6.36

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-10620.json"