CVE-2019-3793 is a vulnerability in Pivotal Software Application Service
Published on April 24, 2019
Invitations Service supports HTTP connections
Pivotal Apps Manager Release, versions 665.0.x prior to 665.0.28, versions 666.0.x prior to 666.0.21, versions 667.0.x prior to 667.0.7, contain an invitation service that accepts HTTP. A remote unauthenticated user could listen to network traffic and gain access to the authorization credentials used to make the invitation requests.
Weakness Type
What is a Man-in-the-Middle / MITM Vulnerability?
The product does not adequately verify the identity of actors at both ends of a communication channel, or does not adequately ensure the integrity of the channel, in a way that allows the channel to be accessed or influenced by an actor that is not an endpoint. In order to establish secure communication between two parties, it is often important to adequately verify the identity of entities at each end of the communication channel. Inadequate or inconsistent verification may result in insufficient or incorrect identification of either communicating entity. This can have negative consequences such as misplaced trust in the entity at the other end of the channel. An attacker can leverage this by interposing between the communicating entities and masquerading as the original entity. In the absence of sufficient verification of identity, such an attacker can eavesdrop and potentially modify the communication between the original entities.
CVE-2019-3793 has been classified to as a Man-in-the-Middle / MITM vulnerability or weakness.
Products Associated with CVE-2019-3793
Want to know whenever a new CVE is published for Pivotal Software Application Service? stack.watch will email you.
Affected Versions
Pivotal Apps Manager:- Version 666 and below 666.0.21 is affected.
- Version 667 and below 667.0.7 is affected.
- Version 665 and below 665.0.28 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.