CVE-2023-1305: Rapid7 InsightCloudSec box object access
An authenticated attacker can leverage an exposed “box” object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-1305?
The severity of CVE-2023-1305 is high with a score of 8.1.
How can an attacker exploit CVE-2023-1305?
An authenticated attacker can leverage an exposed "box" object to read and write arbitrary files from disk, provided those files can be parsed as yaml or JSON.
Which software versions are affected by CVE-2023-1305?
Version 23.2.1 of the Self-Managed version of InsightAppSec, and Managed and SaaS deployments up to version 2023.02.01 of Insightcloudsec.
Has the vulnerability been resolved?
Yes, the vulnerability was resolved on February 1, 2023, for Managed and SaaS deployments, and in version 23.2.1 of the Self-Managed version of InsightAppSec.
Where can I find more information about CVE-2023-1305?
You can find more information about CVE-2023-1305 in the following references: [Link 1](https://docs.divvycloud.com/changelog/23321-release-notes), [Link 2](https://nephosec.com/exploiting-rapid7s-insightcloudsec/)