Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1305


An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.


Published

2023-03-21T17:15:11.727

Last Modified

2025-02-26T17:15:15.230

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-653
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rapid7 insightappsec < 23.2.1 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes

References