Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-1306

Опубликовано: 21 мар. 2023
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rapid7:insightappsec:*:*:*:*:self-managed:*:*:*
Версия до 23.2.1 (исключая)
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:managed:*:*:*
Версия до 2023.02.01 (исключая)
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:saas:*:*:*
Версия до 2023.02.01 (исключая)

EPSS

Процентиль: 49%
0.00261
Низкий

8.8 High

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 8.8
github
почти 3 года назад

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

EPSS

Процентиль: 49%
0.00261
Низкий

8.8 High

CVSS3

Дефекты

CWE-94
CWE-94