help.rapid7.comConfirmation
https://help.rapid7.com/metasploit/release-notes?rid=4.16.0-2019091001 CVE-2019-5642
LOW
MAGICK
Record summary
CVE-2019-5642 has a selected CVSS score of 3.3 (low).
Description
Rapid7 Metasploit Pro version 4.16.0-2019081901 and prior suffers from an instance of CWE-732, wherein the unique server.key is written to the file system during installation with world-readable permissions. This can allow other users of the same system where Metasploit Pro is installed to intercept otherwise private communications to the Metasploit Pro web interface.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Metasploit ProBrowse Rapid7 / Metasploit Pro | CVE List | Through 4.16.0-2019081901 | affected |
References
2nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-5642