PT-2019-16714 · Cloud Foundry · Cloud Foundry Stratos
Published
2019-03-07
·
Updated
2019-10-09
·
CVE-2019-3784
CVSS v3.1
8.2
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Stratos versions prior to 2.3.0
Description
The issue concerns an insecure session that can be spoofed. When Cloud Foundry Stratos is deployed on Cloud Foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.
Recommendations
For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the default embedded SQLite database to minimize the risk of session switching.
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry Stratos