Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-1306


An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.


Published

2023-03-21T17:15:11.797

Last Modified

2025-02-26T17:15:15.517

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rapid7 insightappsec < 23.2.1 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes
Application rapid7 insightcloudsec < 2023.02.01 Yes

References