Beveiligingsadvies

CVE-2023-2273

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-04-26 08:55:36
Laatst bijgewerkt 2025-01-31 16:13:24
Toegewezen door rapid7
CVSS-score 5.8
Status PUBLISHED

Beschrijving

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.