Description
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.
Scores
CVSS v3
8.8
EPSS
0.0023
EPSS Percentile
46.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1188
CWE-384
Status
published
Products (1)
cloudfoundry/stratos
< 2.3.0
Published
Mar 07, 2019
Tracked Since
Feb 18, 2026