VYPR
Medium severity4.4NVD Advisory· Published Jan 22, 2020· Updated Jun 17, 2026

CVE-2019-5647

CVE-2019-5647

Description

The Chrome Plugin for Rapid7 AppSpider can incorrectly keep browser sessions active after recording a macro, even after a restart of the Chrome browser. This behavior could make future session hijacking attempts easier, since the user could believe a session was closed when it was not. This issue affects Rapid7 AppSpider version 3.8.213 and prior versions, and is fixed in version 3.8.215.

Affected products

3
  • cpe:2.3:a:rapid7:appspider:*:*:*:*:enterprise:chrome:*:*
    Range: <=3.8.213
  • Rapid7/Appspider Prollm-fuzzy2 versions
    <=3.8.213, fixed in 3.8.215+ 1 more
    • (no CPE)range: <=3.8.213, fixed in 3.8.215
    • (no CPE)range: 3.8.213

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.