RSS   Vulnerabilities for 'Stratos'   RSS

2019-03-07
 
CVE-2019-3784

CWE-384
 

 
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

 
 
CVE-2019-3783

CWE-255
 

 
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.

 

 >>> Vendor: Cloudfoundry 18 Products
Capi-release
Cf-release
Cf-mysql-release
Routing-release
Bosh azure cpi
Uaa release
Routing release
Cf-deployment
Garden-runc
Staticfile buildpack
User account and authentication
Container runtime
Command line interface
Credhub cli
Stratos
Bosh backup and restore
Cloud controller
Routing


Copyright 2024, cxsecurity.com

 

Back to Top