VYPR

RubyGems package

metasploit-framework

pkg:gem/metasploit-framework

Vulnerabilities (2)

  • CVE-2023-0669KEVFeb 6, 2023
    affected <= 6.0.33

    Fortra (formerly, HelpSystems) GoAnywhere MFT suffers from a pre-authentication command injection vulnerability in the License Response Servlet due to deserializing an arbitrary attacker-controlled object. This issue was patched in version 7.1.2.

  • CVE-2020-7385Apr 23, 2021
    affected < 4.19.0fixed 4.19.0

    By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework ty