JFrog Security Research
< Back

JFSA-2024-001039574 - Mage AI Terminal Server Infoleak

CVE-2024-8072 | CVSS 5.3

JFrog Severity:medium

Discovered ByOri Hollanderof the JFrog Security Research Team

Published 22 Aug, 2024 | Last updated 22 Aug, 2024

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

mage-ai

(,)

Mage AI allows remote unauthenticated attackers to leak the terminal server command history of arbitrary users

Leaking terminal command history for user #1 -

ws://localhost:6789/websocket/terminal?term_name=1--PortalTerminal--Main%20Mage

No mitigations are supplied for this issue

No references are supplied for this issue

< Back