CVE-2023-1306 is a high-severity code execution vulnerability affecting Rapid7 InsightCloudSec. An authenticated attacker can exploit an exposed resource.db() accessor method to inject Python method calls through a Jinja template. This allows for arbitrary code execution, posing a significant risk to the confidentiality, integrity, and availability of affected systems. The vulnerability has a CVSS score of 8.8 (HIGH) due to its network-based attack vector, low attack complexity, and lack of user interaction required. While no active exploitation or public exploit code has been identified, and community discussion is minimal, organizations using InsightCloudSec should prioritize patching to version 23.2.1 or ensure their Managed/SaaS deployments were updated by February 1, 2023.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 23.2.1CPE matchmatch criteria | cpe:2.3:a:rapid7:insightappsec:*:*:*:*:self-managed:*:*:* | ||
< 2023.02.01CPE matchmatch criteria | cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:managed:*:*:* | ||
< 2023.02.01CPE matchmatch criteria | cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:saas:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.