Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5640

Опубликовано: 22 нояб. 2021
Источник: nvd
CVSS3: 3.3
CVSS3: 5.3
CVSS2: 5
EPSS Низкий

Описание

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:nexpose:*:*:*:*:*:*:*:*
Версия до 6.6.114 (исключая)

EPSS

Процентиль: 38%
0.00171
Низкий

3.3 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-200

Связанные уязвимости

CVSS3: 5.3
github
около 4 лет назад

Rapid7 Nexpose versions prior to 6.6.114 suffer from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the inspect element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

EPSS

Процентиль: 38%
0.00171
Низкий

3.3 Low

CVSS3

5.3 Medium

CVSS3

5 Medium

CVSS2

Дефекты

CWE-200
CWE-200