PT-2024-38768 · Rapid7 · Rapid7 Insight Platform
Abhik Makwana
·
Published
2024-09-09
·
Updated
2024-09-17
·
CVE-2024-8042
CVSS v3.1
3.1
Low
| Vector | AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
Rapid7 Insight Platform versions between November 2019 and August 14, 2024
Description:
The issue is related to missing authorization in the Rapid7 Insight Platform, allowing an attacker to intercept local requests and potentially add an empty user group to the incorrect customer. This could be achieved by exploiting the lack of proper authorization when setting the name and description of a new user group.
Recommendations:
For Rapid7 Insight Platform versions between November 2019 and August 14, 2024, update to a version released after August 14, 2024, to resolve the issue. As a temporary workaround, consider restricting access to user group management features until the update is applied.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Insight Platform