CVE-2019-3777: Apps Manager unverified SSL certs in Cloud Controller proxy
Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controller's DNS record could intercept access tokens sent to the Cloud Controller, giving the attacker access to the user's resources in the Cloud Controller
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3777?
CVE-2019-3777 is a vulnerability in Pivotal Application Service (PAS) versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7, and 2.4.x prior to 2.4.3.
What is the severity of CVE-2019-3777?
CVE-2019-3777 has a severity rating of 9.8 (critical).
How does CVE-2019-3777 affect Pivotal Application Service?
CVE-2019-3777 affects Pivotal Application Service by allowing a remote unauthenticated attacker to hijack the Cloud Controller's DNS record and intercept communication.
Which versions of Pivotal Application Service are affected by CVE-2019-3777?
CVE-2019-3777 affects versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7, and 2.4.x prior to 2.4.3 of Pivotal Application Service.
How can I fix CVE-2019-3777?
To fix CVE-2019-3777, upgrade to Pivotal Application Service versions 2.2.12, 2.3.7, or 2.4.3.