Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1304


An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.


Published

2023-03-21T17:15:11.557

Last Modified

2025-02-25T19:15:12.393

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rapid7 insightappsec < 23.2.1 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes

References