CVE-2021-31868
Last modified
CVE-2021-31868 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Nexpose | < 6.6.96 |
References
- https://docs.rapid7.com/release-notes/nexpose/20210804/Release Notes, Vendor Advisory
- https://docs.rapid7.com/release-notes/nexpose/20210804/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31868?
How severe is CVE-2021-31868?
How do I fix CVE-2021-31868?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31862SysAid 20.4.74 allows XSS via the KeepAlive.jsp stamp parame…6.1
- CVE-2021-31863Insufficient input validation in the Git repository integrat…7.5
- CVE-2021-31864Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4…5.3
- CVE-2021-31865Redmine before 4.0.9, 4.1.x before 4.1.3, and 4.2.x before 4…5.3
- CVE-2021-31866Redmine before 4.0.9 and 4.1.x before 4.1.3 allows an attack…5.3
- CVE-2021-31867Pimcore Customer Data Framework version 3.0.0 and earlier su…7.5
- CVE-2021-31869Pimcore AdminBundle version 6.8.0 and earlier suffers from a…7.5
- CVE-2021-3187An issue was discovered in BeyondTrust Privilege Management …8.8
- CVE-2021-31870An issue was discovered in klibc before 2.0.9. Multiplicatio…9.8
- CVE-2021-31871An issue was discovered in klibc before 2.0.9. An integer ov…7.5
- CVE-2021-31872An issue was discovered in klibc before 2.0.9. Multiple poss…9.8
- CVE-2021-31873An issue was discovered in klibc before 2.0.9. Additions in …9.8
Are you affected by CVE-2021-31868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
