CVE-2017-4963

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/06/2017
Last modified:
20/04/2025

Description

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:cloud_foundry_cf-release:*:*:*:*:*:*:*:* 252 (including)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* 2.0.0 (including) 2.7.4.12 (including)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* 3.0.0 (including) 3.11.0 (including)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:bosh:*:* 26 (including)