PT-2024-38768 · Rapid7 · Rapid7 Insight Platform

Abhik Makwana

·

Published

2024-09-09

·

Updated

2024-09-17

·

CVE-2024-8042

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Rapid7 Insight Platform versions between November 2019 and August 14, 2024
Description: The issue is related to missing authorization in the Rapid7 Insight Platform, allowing an attacker to intercept local requests and potentially add an empty user group to the incorrect customer. This could be achieved by exploiting the lack of proper authorization when setting the name and description of a new user group.
Recommendations: For Rapid7 Insight Platform versions between November 2019 and August 14, 2024, update to a version released after August 14, 2024, to resolve the issue. As a temporary workaround, consider restricting access to user group management features until the update is applied.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-8042

Affected Products

Rapid7 Insight Platform