PT-2021-9120 · Rapid7 · Rapid7 Nexpose
Ashutosh Barot
·
Published
2021-11-22
·
Updated
2024-09-17
·
CVE-2019-5640
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rapid7 Nexpose versions prior to 6.6.114
Description
The issue allows an attacker to expose information when a user's session has ended due to inactivity. By using the inspect element browser feature, an attacker can remove the login panel and view the details available in the last webpage visited by the previous user.
Recommendations
For versions prior to 6.6.114, update to version 6.6.114 or later to resolve the issue. As a temporary workaround, consider implementing a shorter session timeout to minimize the window of opportunity for an attacker to exploit the issue. Additionally, restrict access to the inspect element browser feature to minimize the risk of exploitation.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rapid7 Nexpose