Security Advisory

CVE-2023-2273

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2023-04-26 08:55:36
Last updated 2025-01-31 16:13:24
Assigner rapid7
State PUBLISHED

Description

Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.