PT-2023-18671 · Rapid7 · Rapid7 Insight Agent

CVE-2023-2273

·

Publicado

2023-04-26

·

Atualizado

2023-05-04

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Rapid7 Insight Agent versions 3.2.6 and below
Description The issue is related to a Directory Traversal vulnerability. Unsantized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path, potentially allowing an attacker to write arbitrary files.
Recommendations For versions 3.2.6 and below, update to version 3.3.0 to resolve the issue, as it includes safeguards that reject inputs attempting path traversal.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-2273

Produtos afetados

Rapid7 Insight Agent