CVE-2021-4016
Last modified
CVE-2021-4016 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Rapid7 Insight Agent, versions prior to 3.1.3, suffer from an improper access control vulnerability whereby, the user has access to the snapshot directory. An attacker can access, read and copy any of the files in this directory e.g. asset_info.json or file_info.json, leading to a loss of confidentiality. This issue was fixed in Rapid7 Insight Agent 3.1.3.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Insight Agent | < 3.1.3 |
References
- https://docs.rapid7.com/release-notes/insightagent/20220119/Release Notes, Third Party Advisory
- https://docs.rapid7.com/release-notes/insightagent/20220119/Release Notes, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-4016?
How severe is CVE-2021-4016?
How do I fix CVE-2021-4016?
Are you affected by CVE-2021-4016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
