With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter.
References
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2017-05-25T17:00:00

Updated: 2024-08-06T05:39:31.774Z

Reserved: 2015-04-10T00:00:00

Link: CVE-2015-3190

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-05-25T17:29:00.367

Modified: 2024-11-21T02:28:51.990

Link: CVE-2015-3190

cve-icon Redhat

No data.