Описание
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
Ссылки
- Release Notes
- ExploitThird Party Advisory
- Release Notes
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 23.2.1 (исключая)Версия до 2023.02.01 (исключая)Версия до 2023.02.01 (исключая)
Одно из
cpe:2.3:a:rapid7:insightappsec:*:*:*:*:self-managed:*:*:*
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:managed:*:*:*
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:saas:*:*:*
EPSS
Процентиль: 38%
0.00162
Низкий
8.1 High
CVSS3
Дефекты
CWE-653
NVD-CWE-Other
Связанные уязвимости
CVSS3: 8.1
github
больше 2 лет назад
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
EPSS
Процентиль: 38%
0.00162
Низкий
8.1 High
CVSS3
Дефекты
CWE-653
NVD-CWE-Other