CVE-2024-51560

MEDIUM

Wave 2.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

This vulnerability exists in the Wave 2.0 due to improper exception handling for invalid inputs at certain API endpoint. An authenticated remote attacker could exploit this vulnerability by providing invalid inputs for “userId” parameter in the API request leading to generation of error message containing sensitive information on the targeted system.

Scores

CVSS v3 4.3
EPSS 0.0026
EPSS Percentile 48.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-209
Status published
Products (2)
63moons/aero < 120820241550
63moons/wave_2.0 < 1.1.7
Published Nov 04, 2024
Tracked Since Feb 18, 2026