Back

HIGH

Rapid7 Nexpose Insufficient Session Management

Published Aug 21, 2019

Description

Rapid7 Nexpose versions 6.5.50 and prior suffer from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session is still valid after the password change, potentially allowing the attacker who originally compromised the credential to remain logged in and able to cause further damage.

Affected products

Remediation

Vendor solution

This issue is resolved in versions 6.5.51 and later of Rapid7 Nexpose.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Aug 21, 2019
Updated Sep 16, 2024
Reserved Jan 7, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a