LOW
MAGICK
Published Nov 6, 2019
3.3
LOWCVSS 3.1
EPSS 0.31%
Description
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<=4.16.0-2019081901
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rapid7 | Metasploit Pro | n/a |
|
OR
- < 4.16.0
- 4.16.0
- 4.16.0
- 4.16.0
- 4.16.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
This issue is resolved in Metasploit Pro version 4.16.0-2019091001
Weaknesses (1)
References (1)
- https://help.rapid7.com/metasploit/release-notes/?rid=4.16.0-2019091001 x_refsource_CONFIRMRelease NotesVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://help.rapid7.com/metasploit/release-notes/?rid=4.16.0-2019091001 | x_refsource_CONFIRMRelease NotesVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Nov 6, 2019
Updated Sep 17, 2024
Reserved Jan 7, 2019
Link CVE-2019-5642
CISA Vulnrichment
Updated n/a