CVE-2019-3783

HIGH

Cloud Foundry Stratos <2.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.

Scores

CVSS v3 8.8
EPSS 0.0023
EPSS Percentile 46.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1188 CWE-384
Status published
Products (1)
cloudfoundry/stratos < 2.3.0
Published Mar 07, 2019
Tracked Since Feb 18, 2026