← Back to CVE List

CVE-2023-2273

Published: 2023-04-26T09:15Z
Last Modified: 2024-11-21T07:58Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Rapid7 Insight Agent token handler versions 3.2.6 and below, suffer from a Directory Traversal vulnerability whereby unsanitized input from a CLI argument flows into io.ioutil.WriteFile, where it is used as a path. This can result in a Path Traversal vulnerability and allow an attacker to write arbitrary files. This issue is remediated in version 3.3.0 via safe guards that reject inputs that attempt to do path traversal. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt