Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
References
Link | Resource |
---|---|
https://docs.rapid7.com/release-notes/nexpose/20210804/ | Release Notes Vendor Advisory |
https://docs.rapid7.com/release-notes/nexpose/20210804/ | Release Notes Vendor Advisory |
Configurations
History
21 Nov 2024, 06:06
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 5.5
v3 : 4.3 |
References | () https://docs.rapid7.com/release-notes/nexpose/20210804/ - Release Notes, Vendor Advisory |
Information
Published : 2021-08-19 16:15
Updated : 2024-11-21 06:06
NVD link : CVE-2021-31868
Mitre link : CVE-2021-31868
CVE.ORG link : CVE-2021-31868
JSON object : View
Products Affected
rapid7
- nexpose
CWE
CWE-306
Missing Authentication for Critical Function