CVE-2019-5630
Last modified
CVE-2019-5630 is a vulnerability of currently unknown severity. A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.. EPSS estimates a 0.89% chance of exploitation in the next 30 days.
Description
A Cross-Site Request Forgery (CSRF) vulnerability was found in Rapid7 Nexpose InsightVM Security Console versions 6.5.0 through 6.5.68. This issue allows attackers to exploit CSRF vulnerabilities on API endpoints using Flash to circumvent a cross-domain pre-flight OPTIONS request.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rapid7 | Nexpose | >= 6.5.0, <= 6.5.68 |
References
- https://help.rapid7.com/nexpose/en-us/release-notes#6.5.69Release Notes, Vendor Advisory
- https://help.rapid7.com/nexpose/en-us/release-notes#6.5.69Release Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-5630?
How severe is CVE-2019-5630?
How do I fix CVE-2019-5630?
Are you affected by CVE-2019-5630?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
