SB2019110666 - Incorrect permission assignment for critical resource in Rapid7 Metasploit



SB2019110666 - Incorrect permission assignment for critical resource in Rapid7 Metasploit

Published: November 6, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019110666
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Incorrect permission assignment for critical resource (CVE-ID: CVE-2019-5642)

The vulnerability allows a local authenticated user to gain access to sensitive information.

Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.


Remediation

Install update from vendor's website.