CVE-2019-3790
Last modified
CVE-2019-3790 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.. EPSS estimates a 0.66% chance of exploitation in the next 30 days.
Description
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.
Metrics
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Operations Manager | >= 2.2.0, < 2.2.23 |
| Pivotal Software | Operations Manager | >= 2.3.0, < 2.3.16 |
| Pivotal Software | Operations Manager | >= 2.4.0, < 2.4.11 |
| Pivotal Software | Operations Manager | >= 2.5.0, < 2.5.3 |
References
- http://www.securityfocus.com/bid/108512Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2019-3790Vendor Advisory
- http://www.securityfocus.com/bid/108512Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2019-3790Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-3790?
How severe is CVE-2019-3790?
How do I fix CVE-2019-3790?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-3784Cloud Foundry Stratos, versions prior to 2.3.0, contains an …8.2
- CVE-2019-3785Cloud Foundry Cloud Controller, versions prior to 1.78.0, co…8.1
- CVE-2019-3786Cloud Foundry BOSH Backup and Restore CLI, all versions prio…7.1
- CVE-2019-3787Cloud Foundry UAA, versions prior to 73.0.0, falls back to a…8.3
- CVE-2019-3788Cloud Foundry UAA Release, versions prior to 71.0, allows cl…8.7
- CVE-2019-3789Cloud Foundry Routing Release, all versions prior to 0.188.0…6.5
- CVE-2019-3791Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-3792Pivotal Concourse version 5.0.0, contains an API that is vul…6.8
- CVE-2019-3793Pivotal Apps Manager Release, versions 665.0.x prior to 665.…9.8
- CVE-2019-3794Cloud Foundry UAA, versions prior to v73.4.0, does not set a…5.4
- CVE-2019-3795Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior …5.3
- CVE-2019-3796Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2019-3790?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
