CVE-2020-5402

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
27/02/2020
Last modified:
03/03/2020

Description

In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 12.33.0 (excluding)
cpe:2.3:a:cloudfoundry:user_account_and_authentication:*:*:*:*:*:*:*:* 74.14.0 (excluding)


References to Advisories, Solutions, and Tools