Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Path Traversal in Rapid7 InsightConnect Compression Plugin
Vulnerability Description
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rapid7 InsightConnect Compression Plugin 路径遍历漏洞
Vulnerability Description
Rapid7 InsightConnect Compression Plugin是美国Rapid7公司的一个数据压缩插件。 Rapid7 InsightConnect Compression Plugin 2.0.3之前版本存在路径遍历漏洞,该漏洞源于Linux平台上create_archive函数中的路径遍历问题,可能导致经过身份验证的攻击者通过特制文件名输入写入非预期的文件路径,影响限于文件损坏。
CVSS Information
N/A
Vulnerability Type
N/A