CVE-2018-1190
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
04/01/2018
Last modified:
25/05/2021
Description
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | 269 (including) | |
| cpe:2.3:a:pivotal:uaa:*:*:*:*:*:*:*:* | 3.0.0 (including) | 3.20.1 (including) |
| cpe:2.3:a:pivotal:uaa_bosh:*:*:*:*:*:*:*:* | 44 (including) |
To consult the complete list of CPE names with products and versions, see this page



