Miggo Logo

CVE-2023-0242: Velociraptor vulnerable to Missing Authorization

8.8

CVSS Score
3.1

Basic Information

EPSS Score
0.49388%
Published
1/18/2023
Updated
2/1/2023
KEV Status
No
Technology
TechnologyGo

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
www.velocidex.com/golang/velociraptorgo< 0.6.7-50.6.7-5

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

The vulnerability description explicitly identifies the copy() function in vql/filesystem/copy.go as the root cause. The documentation states that while read permissions are checked, write permissions for the destination path are not validated. This matches the CWE-862 (Missing Authorization) classification, as the function fails to enforce required write-access controls. The provided GitHub file paths and function name are repeated in multiple sources (CVE, GHSA, and Velociraptor's own advisory), confirming the target.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

R*pi** V*lo*ir*ptor *llows us*rs to ** *r**t** wit* *i***r*nt privil***s on t** s*rv*r. **ministr*tors *r* **n*r*lly *llow** to run *ny *omm*n* on t** s*rv*r in*lu*in* writin* *r*itr*ry *il*s. *ow*v*r, low*r privil*** us*rs *r* **n*r*lly *or*i***n *r

Reasoning

T** vuln*r**ility **s*ription *xpli*itly i**nti*i*s t** *opy() *un*tion in vql/*il*syst*m/*opy.*o *s t** root **us*. T** *o*um*nt*tion st*t*s t**t w*il* r*** p*rmissions *r* ****k**, writ* p*rmissions *or t** **stin*tion p*t* *r* not v*li**t**. T*is