Lucene search

K
osvGoogleOSV:CVE-2019-3803
HistoryJan 12, 2019 - 12:29 a.m.

CVE-2019-3803

2019-01-1200:29:00
Google
osv.dev
7

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.7%

Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user’s browser history could obtain the access token and use it to authenticate as the user.

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.7%

Related for OSV:CVE-2019-3803