CVE-2019-3783: Cloud Foundry Stratos Deploys With Public Default Session Store Secret
Published Feb 19, 2019
·Updated
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.
Affected Software
1 affected component
Cloudfoundry Stratos<2.3.0
Event History
Mar 7, 2019
CVE Published
06:29 PM
Data Sourced
via NVD·06:29 PM
DescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for Cloud Foundry Stratos?
The vulnerability ID for Cloud Foundry Stratos is CVE-2019-3783.
2
What is the severity of CVE-2019-3783?
The severity of CVE-2019-3783 is high with a severity value of 8.8.
3
How does Cloud Foundry Stratos versions prior to 2.3.0 have a vulnerability?
Cloud Foundry Stratos versions prior to 2.3.0 have a vulnerability where it deploys with a public default session store secret.
4
What can a malicious user do with the default session store secret in Cloud Foundry Stratos?
A malicious user with the default session store secret can brute force another user's current Stratos session and act on behalf of that user.
5
How can I fix the vulnerability in Cloud Foundry Stratos versions prior to 2.3.0?
To fix the vulnerability, upgrade to version 2.3.0 or higher of Cloud Foundry Stratos.