Cloud Foundry Stratos, versions before 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
cloudfoundry stratos |