High severity8.8NVD Advisory· Published Mar 7, 2019· Updated Jun 17, 2026
CVE-2019-3783
CVE-2019-3783
Description
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Cloud Foundry/Stratosv5Range: All
<2.3.0+ 1 more
- (no CPE)range: <2.3.0
- cpe:2.3:a:cloudfoundry:stratos:*:*:*:*:*:*:*:*range: <2.3.0
Patches
Vulnerability mechanics
References
1- www.cloudfoundry.org/blog/cve-2019-3783nvdVendor Advisory
News mentions
0No linked articles in our index yet.