CVE-2021-31868: Rapid7 Nexpose Security Console Ticket Access Authentication Vulnerability
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31868?
CVE-2021-31868 is a vulnerability in Rapid7 Nexpose version 6.6.95 and earlier that allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket.
How severe is CVE-2021-31868?
CVE-2021-31868 has a severity rating of 5.4 (medium).
How can I fix CVE-2021-31868?
To fix CVE-2021-31868, you should upgrade to version 6.6.96 or later of Rapid7 Nexpose, which resolves the vulnerability.
Where can I find more information about CVE-2021-31868?
You can find more information about CVE-2021-31868 in the release notes for Rapid7 Nexpose version 6.6.96, released on August 4, 2021.
What is CWE-306?
CWE-306 is a Common Weakness Enumeration category that represents 'Missing Authentication for Critical Function'.