跳转到帖子

Rapid7 Insight Agent: CVE-2023-2273: Directory Traversal vulnerability

recommended_posts

发布于
  • Members

Rapid7 Insight Agent: CVE-2023-2273: Directory Traversal vulnerability

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:C/A:N)
Published
04/26/2023
Created
05/15/2023
Added
05/15/2023
Modified
04/23/2024

Description

Rapid7 Insight Agent token handler versions 3.2.6 and below on Linux and Mac Operating Systems, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.

Solution(s)

  • rapid7-insightagent-cve-2023-2273

References

  • https://attackerkb.com/topics/cve-2023-2273
  • CVE - 2023-2273
  • https://docs.rapid7.com/release-notes/insightagent/20230425/
  • 查看数 695
  • 已创建
  • 最后回复

参与讨论

你可立刻发布并稍后注册。 如果你有帐户,立刻登录发布帖子。
注意:你的帖子需要版主批准后才能看到。

游客
回帖…