PT-2022-11195 · Rapid7 · Rapid7 Insight Agent

Andreas Welcker

·

Published

2022-01-21

·

Updated

2022-08-05

·

CVE-2021-4016

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Rapid7 Insight Agent versions prior to 3.1.3
Description The issue is related to improper access control, allowing users to access the snapshot directory. An attacker can access, read, and copy files in this directory, such as asset info.json or file info.json, leading to a loss of confidentiality.
Recommendations For versions prior to 3.1.3, update to Rapid7 Insight Agent 3.1.3 to resolve the issue. As a temporary workaround, consider restricting access to the snapshot directory to minimize the risk of exploitation.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2021-4016

Affected Products

Rapid7 Insight Agent