The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user can gain access to a browser session that was supposed to have expired, and access Ops Manager resources.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/108512 | Third Party Advisory VDB Entry |
https://pivotal.io/security/cve-2019-3790 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: dell
Published: 2019-05-28T00:00:00
Updated: 2019-06-06T19:17:33
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3790
JSON object: View
NVD Information
Status : Modified
Published: 2019-06-06T19:29:00.783
Modified: 2019-10-09T23:49:39.663
Link: CVE-2019-3790
JSON object: View
Redhat Information
No data.