Lucene search

K
nvd[email protected]NVD:CVE-2024-8042
HistorySep 09, 2024 - 3:15 p.m.

CVE-2024-8042

2024-09-0915:15:12
CWE-862
web.nvd.nist.gov
2
rapid7
insight platform
authorization
vulnerability
user group

CVSS3

3.1

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

13.4%

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This vulnerability is remediated as of August 14, 2024.

Affected configurations

Nvd
Node
rapid7insight_platformRange2019-11-012024-08-14
VendorProductVersionCPE
rapid7insight_platform*cpe:2.3:a:rapid7:insight_platform:*:*:*:*:*:*:*:*

CVSS3

3.1

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0

Percentile

13.4%

Related for NVD:CVE-2024-8042