Beveiligingsadvies

CVE-2019-3803

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-01-12 01:00:00
Laatst bijgewerkt 2024-09-16 20:36:24
Toegewezen door dell
CVSS-score 4.5
Status PUBLISHED

Beschrijving

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.