CVE-2018-11041

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
25/06/2018
Last modified:
23/08/2018

Description

Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* 4.6.0 (excluding) 4.7.5 (excluding)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* 48 (excluding) 52.9 (excluding)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* 4.7.5 (excluding) 4.10.1 (excluding)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* 52.9 (excluding) 55.1 (excluding)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* 4.10.1 (excluding) 4.19.0 (excluding)
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* 55.1 (excluding) 60 (excluding)


References to Advisories, Solutions, and Tools