CVE-2024-8042 LOW

CVE-2024-8042: Rapid7 Insight Platform Unauthorized Empty Group Creation

Vendor Rapid7
Product Insight Platform
Weakness CWE-862 · Missing authorization
Published September 9, 2024
Last update September 9, 2024

CVSS base score

2.4/10
Attack vector Adjacent
Attack complexity High
Privileges required High
User interaction Required
Confidentiality None
Integrity Low

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:N/I:L/A:N

What the vulnerability does

01Description

Rapid7 Insight Platform versions between November 2019 and August 14, 2024 suffer from missing authorization issues whereby an attacker can intercept local requests to set the name and description of a new user group. This could potentially lead to an empty user group being added to the incorrect customer. This vulnerability is remediated as of August 14, 2024.

Key dates

02Disclosure timeline

September 9, 2024 CVE published
September 9, 2024 Record updated

Related vulnerabilities

04Related CVE