Security Advisory

CVE-2019-3783

8.8
HIGH

Vulnerability Description

Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.
Published Date March 7, 2019
Official Source NIST NVD Advisory