Description
Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is limited to file corruption as content cannot be controlled by the attacker.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Any version before 2.0.3
2.0.3 (custom)
Credits
Jacob Steadman, Rapid7
Jed Starr, Rapid7
References
extensions.rapid7.com/extension/compression