Vulnerability Name: | CVE-2019-3790 (CCN-162289) | ||||||||||||
Assigned: | 2019-05-24 | ||||||||||||
Published: | 2019-05-24 | ||||||||||||
Updated: | 2019-10-09 | ||||||||||||
Summary: | The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources. | ||||||||||||
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) 4.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
| ||||||||||||
Vulnerability Type: | CWE-613 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-3790 Source: BID Type: Third Party Advisory, VDB Entry 108512 Source: XF Type: UNKNOWN pivotal-cve20193790-sec-bypass(162289) Source: CCN Type: Pivotal Web site CVE-2019-3790: Ops Manager uaa client issues tokens after refresh token expiration Source: CONFIRM Type: Vendor Advisory https://pivotal.io/security/cve-2019-3790 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
BACK |