Description
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26581 | In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2020-5402 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T17:03:33.297Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5402
No data.
Status : Modified
Published: 2020-02-27T20:15:11.577
Modified: 2024-11-21T05:34:04.740
Link: CVE-2020-5402
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD