Loading
Generated remediation guidance and an executive summary. No account required.
Pivotal Concourse, all versions prior to 4.2.2, puts the user access token in a url during the login flow. A remote attacker who gains access to a user's browser history could obtain the access token and use it to authenticate as the user.
Use CWE-200, Pivotal Software vendor hub and Concourse product page to widen CVE-2019-3803 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5415, CVE-2018-15798 and CVE-2018-1227 for nearby disclosures in the same product family.