Description
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13429 | Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user. |
References
| Link | Providers |
|---|---|
| https://pivotal.io/security/cve-2019-3803 |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T20:36:24.722Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3803
No data.
Status : Modified
Published: 2019-01-12T00:29:00.197
Modified: 2024-11-21T04:42:34.370
Link: CVE-2019-3803
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD