Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-25352 | Querybook is a Big Data Querying UI, combining collocated table metadata and a simple notebook interface. Querybook's datadocs functionality works by using a Websocket Server. The client talks to this WSS whenever updating/deleting/reading any cells as well as for watching the live status of query executions. Currently the CORS setting allows all origins, which could result in cross-site websocket hijacking and allow attackers to read/edit/remove datadocs of the user. This issue has been addressed in version 3.32.0. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Thu, 04 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pinterest:querybook:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-02T00:48:49.563Z
Reserved: 2024-03-07T14:33:30.036Z
Link: CVE-2024-28251
Updated: 2024-05-23T19:01:17.736Z
Status : Analyzed
Published: 2024-03-14T00:15:33.630
Modified: 2026-06-17T07:21:16.017
Link: CVE-2024-28251
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:15:59Z
-
CWE-345
Insufficient Verification of Data Authenticity
EUVD