PT-2019-16714 · Cloud Foundry · Cloud Foundry Stratos

Published

2019-03-07

·

Updated

2019-10-09

·

CVE-2019-3784

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry Stratos versions prior to 2.3.0
Description The issue concerns an insecure session that can be spoofed. When Cloud Foundry Stratos is deployed on Cloud Foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.
Recommendations For versions prior to 2.3.0, update to version 2.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the default embedded SQLite database to minimize the risk of session switching.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3784

Affected Products

Cloud Foundry Stratos