CVE-2019-3793 affects Pivotal Apps Manager Release versions 665.0.x prior to 665.0.28, 666.0.x prior to 666.0.21, and 667.0.x prior to 667.0.7. The vulnerability lies in the invitation service, which accepts unencrypted HTTP connections. This allows a remote, unauthenticated attacker to intercept network traffic and steal authorization credentials used for invitation requests. This is a critical vulnerability with a CVSS score of 9.8, indicating a high impact on confidentiality, integrity, and availability. The attack requires no user interaction and has low attack complexity, making it easily exploitable over the network. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 665.0.0, < 665.0.28CPE matchmatch criteria | cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:* | ||
>= 666.0.0, < 666.0.21CPE matchmatch criteria | cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:* | ||
>= 667.0.0, < 667.0.7CPE matchmatch criteria | cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:* | ||
>= 665, < 665.0.28CPE match | cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:* | ||
>= 666, < 666.0.21CPE match | cpe:2.3:a:pivotal:apps_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.