PT-2019-16731 · Pivotal · Concourse

Publicado

2019-01-12

·

Atualizado

2019-10-09

·

CVE-2019-3803

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pivotal Concourse versions prior to 4.2.2
Description The issue allows a remote attacker to obtain a user's access token from their browser history during the login flow, potentially leading to authentication as the user.
Recommendations For versions prior to 4.2.2, update to version 4.2.2 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3803

Produtos afetados

Concourse