Rapid7 Nexpose Uncontrolled URL Redirect
CVE-2023-0681

4.3MEDIUM

Key Information:

Vendor

Rapid7

Status
Vendor
CVE Published:
20 March 2023

What is CVE-2023-0681?

Rapid7 InsightVM versions 6.6.178 and lower suffers from an open redirect vulnerability, whereby an attacker has the ability to redirect the user to a site of the attacker’s choice using the ā€˜page’ parameter of the ā€˜data/console/redirect’ component of the application. This issue was resolved in the February, 2023 release of version 6.6.179.Ā 

Affected Version(s)

Nexpose 0 <= 6.6.178

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Beau Taub of 2U, Inc.
.
CVE-2023-0681 : Rapid7 Nexpose Uncontrolled URL Redirect