Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-1305— Rapid7 InsightCloudSec box object access

EPSS 0.33% · P56
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-1305

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Rapid7 InsightCloudSec box object access
Source: NVD (National Vulnerability Database)
Vulnerability Description
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
不充分的划分
Source: NVD (National Vulnerability Database)
Vulnerability Title
InsightCloudSec 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
InsightCloudSec是InsightCloudSec公司的一个完全集成的云原生安全平台。 InsightCloudSec 23.3.21之前版本存在安全漏洞,该漏洞源于攻击者可以利用暴露的“box”对象从磁盘读取和写入任意文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Rapid7InsightCloudSec 0 ~ 23.2.0 -

II. Public POCs for CVE-2023-1305

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-1305

登录查看更多情报信息。

Same Patch Batch · Rapid7 · 2023-03-21 · 3 CVEs total

CVE-2023-1304Rapid7 InsightCloudSec getattr() method access
CVE-2023-1306Rapid7 InsightCloudSec resource.db() method access

IV. Related Vulnerabilities

V. Comments for CVE-2023-1305

No comments yet


Leave a comment