ASA-2019-00559 – VMware ESXi and VMware vCenter: Information disclosure vulnerability

An information disclosure vulnerability in clients arising from insufficient session expiration. An attacker with physical access or an ability to mimic a websocket connection to a user’s browser may be able to obtain control of a VM Console after the user has logged out or their session has timed out.