Rapid7 InsightVM
cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*
- < 8.34.0
A signature verification vulnerability has been identified in Rapid7 InsightVM versions prior to 8.34.0. The issue resides in the Assertion Consumer Service (ACS) cloud endpoint, where the application processes unsigned assertions. This flaw could enable an attacker to gain unauthorized access to InsightVM accounts linked to 'Security Console' installations, potentially leading to a full account takeover. The vulnerability allows the issuance of session cookies that grant access to the targeted user accounts.
Exploitation of this vulnerability could result in unauthorized access to InsightVM accounts and full account takeover.
Users can upgrade to Rapid7 InsightVM version 8.34.0 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.