Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-5647

Опубликовано: 22 янв. 2020
Источник: nvd
CVSS3: 4.4
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rapid7:appspider:*:*:*:*:enterprise:chrome:*:*
Версия до 3.8.213 (включая)

EPSS

Процентиль: 31%
0.00117
Низкий

4.4 Medium

CVSS3

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-613
CWE-613

Связанные уязвимости

github
больше 3 лет назад

The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.

EPSS

Процентиль: 31%
0.00117
Низкий

4.4 Medium

CVSS3

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-613
CWE-613