Vulnerability CVE-2024-42056


Published: 2024-08-22

Description:
Retool (self-hosted enterprise) through 3.40.0 inserts resource authentication credentials into sent data. Credentials for users with "Use" permissions can be discovered (by an authenticated attacker) via the /api/resources endpoint. The earliest affected version is 3.18.1.

 References:
https://docs.retool.com/releases
https://docs.retool.com/disclosures/cve-2024-42056

Copyright 2026, cxsecurity.com

 

Back to Top