CVE-2021-3619 LOW

CVE-2021-3619: Rapid7 Velociraptor Notebooks Authenticated Persistent XSS

Vendor Rapid7
Product Velociraptor
Weakness CWE-79 · XSS
Published August 17, 2021
Last update September 17, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

What the vulnerability does

01Description

Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.

Key dates

02Disclosure timeline

August 17, 2021 CVE published
September 17, 2024 Record updated