CVE-2019-3784
07.03.2019, 18:29
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | stratos | 𝑥 < 2.3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration