Vulnerabilities
Vulnerable Software
Rapid7:  >> Velociraptor  >> 0.2.8  Security Vulnerabilities
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlink to another file and have the Velociraptor client overwrite the other file. This issue was resolved in Velociraptor 0.6.5-2.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-07-29
The Velociraptor GUI contains an editor suggestion feature that can display the description field of a VQL function, plugin or artifact. This field was not properly sanitized and can lead to cross-site scripting (XSS). This issue was resolved in Velociraptor 0.6.5-2.
CVSS Score
4.8
EPSS Score
0.005
Published
2022-07-29
Rapid7 Velociraptor 0.5.9 and prior is vulnerable to a post-authentication persistent cross-site scripting (XSS) issue, where an authenticated user could abuse MIME filetype sniffing to embed executable code on a malicious upload. This issue was fixed in version 0.6.0. Note that login rights to Velociraptor is nearly always reserved for trusted and verified users with IT security backgrounds.
CVSS Score
3.5
EPSS Score
0.005
Published
2021-07-22


Contact Us

Shodan ® - All rights reserved