CVE-2018-11041
Severity CVSS v4.0:
Pending analysis
Type:
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
25/06/2018
Last modified:
23/08/2018
Description
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
5.80
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* | 4.6.0 (excluding) | 4.7.5 (excluding) |
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* | 48 (excluding) | 52.9 (excluding) |
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* | 4.7.5 (excluding) | 4.10.1 (excluding) |
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* | 52.9 (excluding) | 55.1 (excluding) |
cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* | 4.10.1 (excluding) | 4.19.0 (excluding) |
cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* | 55.1 (excluding) | 60 (excluding) |
To consult the complete list of CPE names with products and versions, see this page