Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mqj-h5x5-v4fc

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

EPSS

Процентиль: 40%
0.00181
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-384

Связанные уязвимости

CVSS3: 8.2
nvd
почти 7 лет назад

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

EPSS

Процентиль: 40%
0.00181
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-384