Vulnerability Description
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Application Service | >= 665.0.0, < 665.0.28 |
Related Weaknesses (CWE)
References
- https://pivotal.io/security/cve-2019-3793Vendor Advisory
- https://pivotal.io/security/cve-2019-3793Vendor Advisory
FAQ
What is CVE-2019-3793?
CVE-2019-3793 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unaut...
How severe is CVE-2019-3793?
CVE-2019-3793 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-3793?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Application Service.