Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
2019-11-06T19:15:12.360
2024-11-21T04:45:17.527
Modified
CVSSv3.1: 3.3 (LOW)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | rapid7 | metasploit | < 4.16.0 | Yes |
Application | rapid7 | metasploit | 4.16.0 | Yes |
Application | rapid7 | metasploit | 4.16.0 | Yes |
Application | rapid7 | metasploit | 4.16.0 | Yes |
Application | rapid7 | metasploit | 4.16.0 | Yes |