8.1

CVE-2023-1305

Exploit

Rapid7 InsightCloudSec box object access

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Rapid7 ≫ Insightappsec SwEdition self-managed Version < 23.2.1
Rapid7 ≫ Insightcloudsec SwEdition managed Version < 2023.02.01
Rapid7 ≫ Insightcloudsec SwEdition saas Version < 2023.02.01
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.78% 0.51
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CISA-ADP 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CWE-653 Improper Isolation or Compartmentalization

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

https://docs.divvycloud.com/changelog/23321-release-notes
Release Notes
https://nephosec.com/exploiting-rapid7s-insightcloudsec/
Third Party Advisory
Exploit