CVE-2019-3783

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
07/03/2019
Last modified:
19/10/2020

Description

Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:stratos:*:*:*:*:*:*:*:* 2.3.0 (excluding)


References to Advisories, Solutions, and Tools