PT-2019-17796 · Rapid7 · Rapid7 Nexpose
Published
2019-08-21
·
Updated
2024-09-16
·
CVE-2019-5638
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Nexpose versions 6.5.50 and prior
Description
The issue arises from insufficient session expiration when an administrator performs a security-relevant edit on an existing, logged-on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session remains valid after the password change. This potentially allows the attacker who originally compromised the credential to remain logged in and cause further damage.
Recommendations
For versions 6.5.50 and prior, consider implementing a mechanism to expire user sessions after a security-relevant edit, such as a password change, to prevent potential further damage from compromised credentials. As a temporary workaround, consider manually logging off users after their credentials have been changed due to a security incident.
Fix
Insufficient Session Expiration
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Nexpose