Описание
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.0.2 (исключая)
Одновременно
cpe:2.3:a:rapid7:insight_agent:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
EPSS
Процентиль: 0%
0.00075
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-732
Связанные уязвимости
CVSS3: 5.5
github
5 месяцев назад
The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any locally authenticated standard user.
EPSS
Процентиль: 0%
0.00075
Низкий
5.5 Medium
CVSS3
Дефекты
CWE-732