Rapid7 InsightCloudSec box object access
CVE-2023-1305
Key Information:
- Vendor
Rapid7
- Status
- Vendor
- CVE Published:
- 21 March 2023
Badges
What is CVE-2023-1305?
An exposed 'box' object vulnerability in Rapid7 InsightCloudSec allows authenticated attackers to read and write arbitrary files on the disk. These files must be readable as YAML or JSON. This vulnerability was patched in the Managed and SaaS deployments on February 1, 2023, and in the Self-Managed version in release 23.2.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
InsightCloudSec 0 <= 23.2.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
