Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-4016

Опубликовано: 21 янв. 2022
Источник: nvd
CVSS3: 4
CVSS3: 3.3
CVSS2: 2.1
EPSS Низкий

Описание

Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue was fixed in Rapid7 Insight Agent 3.1.3.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
Версия до 3.1.3 (исключая)

EPSS

Процентиль: 17%
0.00054
Низкий

4 Medium

CVSS3

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-284
NVD-CWE-Other

Связанные уязвимости

CVSS3: 3.3
github
около 4 лет назад

Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue was fixed in Rapid7 Insight Agent 3.1.3.

EPSS

Процентиль: 17%
0.00054
Низкий

4 Medium

CVSS3

3.3 Low

CVSS3

2.1 Low

CVSS2

Дефекты

CWE-284
NVD-CWE-Other