CVE-2021-31868
Last modified
CVE-2021-31868 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
Rapid7 Nexpose version 6.6.95 and earlier allows authenticated users of the Security Console to view and edit any ticket in the legacy ticketing feature, regardless of the assignment of the ticket. This issue was resolved in version 6.6.96, released on August 4, 2021.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Nexpose | < 6.6.96 |
References
- https://docs.rapid7.com/release-notes/nexpose/20210804/Release Notes, Vendor Advisory
- https://docs.rapid7.com/release-notes/nexpose/20210804/Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31868?
How severe is CVE-2021-31868?
How do I fix CVE-2021-31868?
Are you affected by CVE-2021-31868?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
