CVE-2019-3784

HIGH

Cloud Foundry Stratos <2.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2019-3784

Scores

CVSS v3 8.2
EPSS 0.0108
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Details

CWE
CWE-384
Status published
Products (1)
cloudfoundry/stratos < 2.3.0
Published Mar 07, 2019
Tracked Since Feb 18, 2026