CVE-2019-5647 - CVE House
Back to Database
Status published Medium CVE-2019-5647

Rapid7 AppSpider Chrome Plugin Insufficient Session Expiration

Vulnerability Description

The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-5647

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

AppSpider
Vulnerable Versions:
3.8.213

Timeline

Official Publish: January 22nd, 2020
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)