CVE-2024-28251 is a cross-site WebSocket hijacking vulnerability affecting Querybook, a Big Data Querying UI. The vulnerability stems from overly permissive CORS settings in Querybook's datadocs functionality, allowing all origins to interact with its WebSocket server. This flaw could enable attackers to read, edit, or remove user datadocs, leading to a high-severity impact with a CVSS score of 7.3. While there are no known active exploits, exploit code, or significant community discussion, users are strongly advised to upgrade to version 3.32.0 to mitigate this risk, as no workarounds exist.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.32.0CPE matchmatch criteria | cpe:2.3:a:pinterest:querybook:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.