PT-2019-17790 · Rapid7 · Nexpose Insightvm Security Console
Rodney Beede
·
Published
2019-07-03
·
Updated
2019-10-09
·
CVE-2019-5630
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68
Description
A Cross-Site Request Forgery (CSRF) issue was discovered, allowing attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.
Recommendations
For versions 6.5.0 through 6.5.68, consider disabling the use of Flash to mitigate the risk of exploitation until a patch is available. Restrict access to API endpoints to minimize the risk of CSRF attacks.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nexpose Insightvm Security Console