PT-2019-16720 · Pivotal · Pivotal Ops Manager

Publicado

2019-06-06

·

Atualizado

2019-10-09

·

CVE-2019-3790

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Ops Manager versions prior to 2.2.23 Pivotal Ops Manager versions prior to 2.3.16 Pivotal Ops Manager versions prior to 2.4.11 Pivotal Ops Manager versions prior to 2.5.3
Description The issue concerns configuration that circumvents refresh token expiration, allowing a remote authenticated user to gain access to a browser session that was supposed to have expired and access Ops Manager resources.
Recommendations For versions prior to 2.2.23, update to version 2.2.23 or later. For versions prior to 2.3.16, update to version 2.3.16 or later. For versions prior to 2.4.11, update to version 2.4.11 or later. For versions prior to 2.5.3, update to version 2.5.3 or later.

Correção

Insufficient Session Expiration

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3790

Produtos afetados

Pivotal Ops Manager