Products
Rapid7 Insight Platform
- November 2019 - August 14, 2024
Source
cve@rapid7.com
Tags
CVE-2024-8042 details
Published : Sept. 9, 2024, 3:15 p.m.
Last Modified : Sept. 9, 2024, 6:30 p.m.
Last Modified : Sept. 9, 2024, 6:30 p.m.
Description
Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This vulnerability is remediated as of August 14, 2024.
CVSS Score
1 | 2.4 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-862 | Missing Authorization | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
CVSS Data
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
HIGH
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Base Score
2.4
Exploitability Score
0.7
Impact Score
1.4
Base Severity
LOW
Vector String : CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N
References
URL | Source |
---|---|
https://cwe.mitre.org/data/definitions/862.html | cve@rapid7.com |
This website uses the NVD API, but is not approved or certified by it.