Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Lucaddepar

#37892de 53,632
7.4CVSS total
Vulnerabilidades · 1
PT-2019-17785
7.4
2019-04-24
Rapid7 · Metasploit Framework · CVE-2019-5624
**Name of the Vulnerable Software and Affected Versions** Rapid7 Metasploit Framework versions 4.14.0 and prior versions **Description** The issue is related to improper limitation of a pathname to a restricted directory, also known as a path traversal vulnerability, in the Zip import function of Metasploit. This can allow an attacker to execute arbitrary code in Metasploit at the privilege level of the user running Metasploit. **Recommendations** For Rapid7 Metasploit Framework versions 4.14.0 and prior versions, update to a version that includes the fix for the Zip import function vulnerability. At the moment, there is no information about a newer version that contains a fix for this vulnerability.