Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user
References
Link | Resource |
---|---|
https://docs.rapid7.com/release-notes/insightvm/20220830/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: rapid7
Published: 2022-08-30T00:00:00
Updated: 2022-09-21T14:45:14
Reserved: 2019-01-07T00:00:00
Link: CVE-2019-5641
JSON object: View
NVD Information
Status : Analyzed
Published: 2022-09-21T15:15:10.243
Modified: 2022-09-23T15:10:21.803
Link: CVE-2019-5641
JSON object: View
Redhat Information
No data.