Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
References
Link | Resource |
---|---|
https://docs.rapid7.com/release-notes/nexpose/20210804/ | Release Notes Vendor Advisory |
Configurations
Information
Published : 2021-08-19 09:15
Updated : 2021-08-25 19:14
NVD link : CVE-2021-31868
Mitre link : CVE-2021-31868
JSON object : View
CWE
CWE-306
Missing Authentication for Critical Function
Products Affected
rapid7
- nexpose