Back

MEDIUM

Rapid7 InsightVM Information Disclosure after Logout

Published Sep 21, 2022

Description

Rapid7 InsightVM suffers from an information exposure issue whereby, when the user's session has ended due to inactivity, an attacker can use the Inspect Element browser feature to remove the login panel and view the details available in the last webpage visited by previous user

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner rapid7
Published Sep 21, 2022
Updated May 29, 2025
Reserved Jan 7, 2019
CISA Vulnrichment
Updated May 27, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a