blog.doyensec.com
https://blog.doyensec.com/2019/04/24/rubyzip-bug.html CVE-2019-5624
HIGH
Rapid7 Metasploit Framework Zip Import Directory Traversal
Record summary
CVE-2019-5624 has a selected CVSS score of 7.3 (high); EIP currently links 1 repository PoC.
Description
Rapid7 Metasploit Framework suffers from an instance of CWE-22, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in the Zip import function of Metasploit. Exploiting this vulnerability can allow an attacker to execute arbitrary code in Metasploit at the privilege level of the user running Metasploit. This issue affects: Rapid7 Metasploit Framework version 4.14.0 and prior versions.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Metasploit FrameworkBrowse Rapid7 / Metasploit Framework | CVE List | 4.14.0 to ≤ 4.14.0 | affected |
Proofs of concept
1Repository PoCs
GitHubVoidSec/CVE-2019-5624Repository PoCby VoidSecStars: 13Not analyzed1 file
References
4github.comConfirmation
https://github.com/rapid7/metasploit-framework/pull/11716 help.rapid7.comConfirmation
https://help.rapid7.com/metasploit/release-notes/archive/2019/04 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-5624