CVE-2022-24414

HIGH

Dell EMC CloudLink <7.1.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Dell EMC CloudLink 7.1.3 and all earlier versions, Auth Token is exposed in GET requests. These request parameters can get logged in reverse proxies and server logs. Attackers may potentially use these tokens to access CloudLink server. Tokens should not be used in request URL to avoid such attacks.

Scores

CVSS v3 7.6
EPSS 0.0033
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L

Details

CWE
CWE-200 CWE-598
Status published
Products (1)
dell/cloudlink < 7.1.3
Published May 26, 2022
Tracked Since Feb 18, 2026