Skip to main content

CVE-2024-42056

Disclosure of CVE-2024-42056.

Certain versions of Self-hosted Retool for Enterprise between 3.18.1 and 3.40.0 insert resource authentication credentials into sent data. This could allow remote authenticated attackers to access resource authentication credentials for users with Use permissions via the /api/resources endpoint.

DisclosureDetails
Vulnerability TypeInsertion of Sensitive Information Into Sent Data.
Vendor of ProductRetool.
Affected Product Code BaseView affected release versions.
Affected ComponentSelf-hosted Retool organizations on Enterprise plan.
Attack TypeRemote.
ImpactInformation Disclosure.
Referencehttps://docs.retool.com/releases
DiscovererAnubhav Sharma. This vulnerability was also independently discovered by 6mile

Affected release versions

ReleaseRelease versions
3.183.18.1 to 3.18.23
3.203.20.1 to 3.20.18
3.223.22.1 to 3.22.21
3.243.24.1 to 3.24.22
3.263.26.4 to 3.26.14
3.283.28.3 to 3.28.15
3.303.30.1 to 3.30.15
3.323.32.1 to 3.32.12
3.333.33.1-stable to 3.33.18-stable
3.363.36.0-edge to 3.36.1-edge
3.373.37.0-edge
3.383.38.0-edge
3.393.39.0-edge
3.403.40.0-edge