Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31868

Опубликовано: 19 авг. 2021
Источник: nvd
CVSS3: 4.3
CVSS3: 5.4
CVSS2: 5.5
EPSS Низкий

Описание

Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*
Версия до 6.6.96 (исключая)

EPSS

Процентиль: 31%
0.00117
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-306
CWE-306

Связанные уязвимости

github
больше 3 лет назад

Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.

EPSS

Процентиль: 31%
0.00117
Низкий

4.3 Medium

CVSS3

5.4 Medium

CVSS3

5.5 Medium

CVSS2

Дефекты

CWE-306
CWE-306