CVE-2019-5642: MAGICK
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for Rapid7 Metasploit Pro?
The vulnerability ID for Rapid7 Metasploit Pro is CVE-2019-5642.
What is the severity of CVE-2019-5642?
The severity of CVE-2019-5642 is low, with a severity value of 3.3.
What is the CWE for CVE-2019-5642?
The CWE for CVE-2019-5642 is CWE-732.
What is the affected version of Rapid7 Metasploit Pro?
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior are affected.
How can the vulnerability in Rapid7 Metasploit Pro be exploited?
The vulnerability in Rapid7 Metasploit Pro allows other users of the same system to intercept sensitive information due to world-readable permissions on the server.key file.