漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Rapid7 Insight Platform Privilege Escalation Vulnerability
Vulnerability Description
Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible through the platform's User Interface). This vulnerability has been fixed as of November 13th 2024.
CVSS Information
N/A
Vulnerability Type
授权机制缺失
Vulnerability Title
Rapid7 Insight Platform 安全漏洞
Vulnerability Description
Rapid7 Insight Platform是美国Rapid7公司的一个用于管理个人资料、用户、产品、API 密钥和设置的平台。 Rapid7 Insight Platform存在安全漏洞,该漏洞源于缺乏授权检查。攻击者利用该漏洞可以提升权限。
CVSS Information
N/A
Vulnerability Type
N/A