CVE-2024-7569
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
- EPSS probability
- 1.74%
- CWE
- CWE-922, CWE-215
- Published
- 2024-08-13
- Last modified
- 2026-03-13
Affected products
- Ivanti ITSM
- Ivanti ITSM
Weakness type
Related vulnerabilities
- CVE-2023-32191 — rke's credentials are stored in the RKE1 Cluster state ConfigMap
- CVE-2022-0724 — Insecure Storage of Sensitive Information in microweber/microweber
- CVE-2024-3501 — Exposure of Sensitive Information in lunary-ai/lunary
- CVE-2024-10943 — FactoryTalk® Updater Authentication Bypass
- CVE-2025-10971 — Insecure Storage of Sensitive Information
- CVE-2023-43634 — Config Partition Not Protected by Measured Boot
- CVE-2023-43633 — Debug Functions Unlockable Without Triggering Measured Boot
- CVE-2023-43631 — SSH as Root Unlockable Without Triggering Measured Boot