CVE-2017-5244
Summary
| CVE | CVE-2017-5244 |
|---|---|
| State | PUBLISHED |
| Assigner | rapid7 |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-15 14:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running Metasploit tasks by getting an authenticated user to execute JavaScript. As of Metasploit 4.14.0 (Update 2017061301), the routes for stopping tasks only allow POST requests, which validate the presence of a secret token to prevent CSRF attacks. |
Risk And Classification
Primary CVSS: v3.0 3.5 LOW from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
Problem Types: CWE-352 | CWE-352 CWE-352 (Cross-Site Request Forgery)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 3.5 | LOW | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L |
| 2.0 | [email protected] | Primary | 3.5 | AV:N/AC:M/Au:S/C:N/I:N/A:P |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
NoneAvailability
LowCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
SingleConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:M/Au:S/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rapid7 | Metasploit | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Rapid7 | Metasploit Pro Express And Community Editions | affected < 4.14.0 (Update 2017061301) | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Help @ Rapid7 | af854a3a-2127-422b-91ae-364da2661108 | community.rapid7.com | Exploit, VDB Entry, Vendor Advisory |
| Vulnerability in Metasploit Project aka CVE-2017-5244 – Seekurity | af854a3a-2127-422b-91ae-364da2661108 | www.seekurity.com | Third Party Advisory |
| Multiple Rapid7 Metasploit Editions CVE-2017-5244 Cross Site Request Forgery Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.