Information Exposure Through Query Strings in GET Request vulnerability in Broadcom DX NetOps Spectrum on Windows, Linux
openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server ro
An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication
Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges
Tugtainer is a self-hosted app for automating updates of Docker containers. In versions prior to 1.16.1, the password au
Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut
An unauthenticated remote attacker can obtain valid session tokens because they are exposed in plaintext within the URL
immich is a high performance self-hosted photo and video management solution. Prior to version 2.6.0, the Immich applica
Nhost is an open source Firebase alternative with GraphQL. Prior to 0.48.0, the auth service's OAuth provider callback f
Use of GET Request Method With Sensitive Query Strings vulnerability in Apache OpenMeetings. The REST login endpoint us
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t
Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont
The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query
IBM Engineering AI Hub 1.0.0, 1.1.0, and 1.2.0 could allow a remote attacker to obtain sensitive information due to the
Grav API Plugin is a RESTful API for Grav CMS that provides full headless access to your site's content. Prior to 1.0.0
Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc.
An issue in Key Systems Inc Global Facilities Management Software v.20230721a allows a remote attacker to obtain sensiti
WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php comp
When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app
A use of get request method with sensitive query strings vulnerability in volume encryption of Synology Storage Manager
An information exposure vulnerability exists in Vulnerability in HCL Software ZIE for Web. The application transmits s
IBM Aspera Orchestrator 3.0.0 through 4.1.2 stores sensitive information in URL parameters. This may lead to information
nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-
Medical Practice Management System developed by Le-yan has a Sensitive Data in URL vulnerability. Unauthenticated remote
Certain requests pass the authentication token in the URL as string query parameter, making it vulnerable to theft throu
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik
An attacker can extract user email addresses (PII) exposed in base64 encoding via the state parameter in the OAuth callb
Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyControlle
PinchTab is a standalone HTTP server that gives AI agents direct control over a Chrome browser. PinchTab `v0.7.8` throug
A vulnerability was detected in django-tastypie up to 0.15.1. Impacted is the function ApiKeyAuthentication of the file
IBM Sterling Partner Engagement Manager 6.2.3.0 through 6.2.3.5 and 6.2.4.0 through 6.2.4.2 could allow an attacker to o
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 could allow an attacker to obtain sensitive information from
A flaw was found in the Quay config-tool's GitLab OAuth validator. This vulnerability causes sensitive credentials, spec
HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive
Plane is an an open-source project management tool. Prior to 1.3.0, a vulnerability was identified in Plane's authentica
SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user sess
Frequently Asked Questions
What is CWE-598?
CWE-598 (CWE-598) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-598?
There are 36 CVE records associated with CWE-598 in our database. Of these, 4 are critical severity, 13 are high severity, and 12 are medium severity.
How can I protect against CWE-598 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-598 using AI-powered security agents.
Detect CWE-598 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-598 vulnerabilities across your infrastructure.
Get Started