CVE-2023-1305

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2023
Last modified:
26/02/2025

Description

An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rapid7:insightappsec:*:*:*:*:self-managed:*:*:* 23.2.1 (excluding)
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:managed:*:*:* 2023.02.01 (excluding)
cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:saas:*:*:* 2023.02.01 (excluding)