CVE-2021-3844
Published on: Not Yet Published
Last Modified on: 03/30/2023 05:00:00 PM UTC
Certain versions of Insightvm from Rapid7 contain the following vulnerability:
Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a security relevant edit on an existing, logged on user. For example, if a user's password is changed by an administrator due to an otherwise unrelated credential leak, that user account's current session is still valid after the password change, potentially allowing the attacker who originally compromised the credential to remain logged in and able to cause further damage. This vulnerability is mitigated by the use of the Platform Login feature. This issue is related to CVE-2019-5638.
- CVE-2021-3844 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Rapid7 - InsightVM version < 6.5.50
CVSS3 Score: 5.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | LOW | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Enable InsightVM Platform Login | InsightVM Documentation | docs.rapid7.com text/html |
![]() |
cve-website | www.cve.org text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Rapid7 | Insightvm | All | All | All | All |
- cpe:2.3:a:rapid7:insightvm:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-3844 : Rapid7 InsightVM suffers from insufficient session expiration when an administrator performs a secu… twitter.com/i/web/status/1… | 2023-03-24 17:07:36 |
![]() |
CVE-2021-3844 | 2023-03-24 18:38:41 |