VYPR
High severity8.2NVD Advisory· Published Mar 7, 2019· Updated Jun 17, 2026

CVE-2019-3784

CVE-2019-3784

Description

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Cloud Foundry/Stratosv5
    Range: All
  • cpe:2.3:a:cloudfoundry:stratos:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cloudfoundry:stratos:*:*:*:*:*:*:*:*range: <2.3.0
    • (no CPE)range: <2.3.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.