CVE-2024-11401

CVSS V2 None CVSS V3 None
Description
Rapid7 Insight Platform versions prior to November 13th 2024, suffer from a privilege escalation vulnerability whereby, due to a lack of authorization checks, an attacker can successfully update the password policy in the platform settings as a standard user by crafting an API (the functionality was not possible through the platform's User Interface). This vulnerability has been fixed as of November 13th 2024.
Overview
  • CVE ID
  • CVE-2024-11401
  • Assigner
  • rapid7
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-12-11T09:46:29.398Z
  • Last Modified Date
  • 2024-12-11T15:08:28.354Z
References
History
Created Old Value New Value Data Type Notes
2024-12-12 13:35:55 Added to TrackCVE