Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
References
Link | Resource |
---|---|
https://help.rapid7.com/metasploit/release-notes/?rid=4.16.0-2019091001 | Release Notes Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-11-06 11:15
Updated : 2019-11-13 06:28
NVD link : CVE-2019-5642
Mitre link : CVE-2019-5642
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
rapid7
- metasploit