Description
Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-0894 | Pivotal Cloud Foundry (PCF) Ops Manager before 1.5.14 and 1.6.x before 1.6.9 uses the same cookie-encryption key across different customers' installations, which allows remote attackers to bypass session authentication by leveraging knowledge of this key from another installation. |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-05T22:30:05.133Z
Reserved: 2015-12-17T00:00:00.000Z
Link: CVE-2016-0883
No data.
Status : Deferred
Published: 2016-09-18T02:59:00.150
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-0883
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD