
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability (CVE-2019-5645) was discovered in Rapid7's Metasploit Framework HTTP handler that allows attackers to cause a denial of service condition. The vulnerability affects Metasploit Framework versions up to and including 5.0.27. When exploited, an attacker can send specially crafted HTTP GET requests to a listening Metasploit HTTP handler to register arbitrary regular expressions (Metasploit PR, NVD).
The vulnerability stems from improper handling of regular expressions in the HTTP handler component. When a specially crafted HTTP GET request is sent to a listening Metasploit HTTP handler, an attacker can register arbitrary regular expressions that are then evaluated by the server. The vulnerability has been assigned a CVSS v3.1 Base Score of 7.5 (HIGH) with the vector string: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (NVD).
When successfully exploited, this vulnerability can either prevent new HTTP handler sessions from being established or cause resource exhaustion on the Metasploit server. This effectively creates a denial of service condition that impacts the availability of the affected Metasploit instance (NVD).
The vulnerability can be exploited remotely by sending specially crafted HTTP GET requests to a listening Metasploit HTTP handler. No authentication is required to exploit this vulnerability, making it relatively easy to execute an attack (NVD).
The vulnerability was patched in a pull request to the Metasploit Framework repository. Users should upgrade to versions newer than 5.0.27 to mitigate this vulnerability (Metasploit PR).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."