Rapid7 Insight Agent token handler... CVE-2023-2273

- AV AC AU C I A
发布: 2023-04-26
修订: 2023-05-04

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.

0%
暂无可用Exp或PoC
当前有1条受影响产品信息