CVE-2023-2273
26.04.2023, 09:15
Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal.
| Vendor | Product | Version |
|---|---|---|
| rapid7 | insight_agent | 𝑥 < 3.3.0 |
𝑥
= Vulnerable software versions