CVE Vulnerabilities

CVE-2019-3777

Improper Certificate Validation

Published: Mar 07, 2019 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Pivotal Application Service (PAS), versions 2.2.x prior to 2.2.12, 2.3.x prior to 2.3.7 and 2.4.x prior to 2.4.3, contain apps manager that uses a cloud controller proxy that fails to verify SSL certs. A remote unauthenticated attacker that could hijack the Cloud Controllers DNS record could intercept access tokens sent to the Cloud Controller, giving the attacker access to the users resources in the Cloud Controller

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

NameVendorStart VersionEnd Version
Application_servicePivotal_software2.2.0 (including)2.2.12 (excluding)
Application_servicePivotal_software2.3.0 (including)2.3.7 (excluding)
Application_servicePivotal_software2.4.0 (including)2.4.3 (excluding)

Potential Mitigations

References