Description
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
Published: 2018-06-25
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-5791 Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
Github GHSA Github GHSA GHSA-xh4m-99qp-w483 Cloud Foundry UAA open redirect
History

No history.

Subscriptions

Pivotal Software Cloud Foundry Uaa Cloud Foundry Uaa-release
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T23:11:54.199Z

Reserved: 2018-05-14T00:00:00.000Z

Link: CVE-2018-11041

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-25T15:29:00.410

Modified: 2024-11-21T03:42:33.163

Link: CVE-2018-11041

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses