VYPR
High severity8.8NVD Advisory· Published Mar 21, 2023· Updated Jun 17, 2026

CVE-2023-1306

CVE-2023-1306

Description

An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February 1, 2023, and in version 23.2.1 of the Self-Managed version of InsightCloudSec.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • Range: 23.2.1
  • Rapid7/InsightCloudSeccpe-rescue3 versions
    0+ 2 more
    • (no CPE)range: 0
    • cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:managed:*:*:*range: <2023.02.01
    • cpe:2.3:a:rapid7:insightcloudsec:*:*:*:*:saas:*:*:*range: <2023.02.01
  • cpe:2.3:a:rapid7:insightappsec:*:*:*:*:self-managed:*:*:*
    Range: <23.2.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.