CVE Database
/

CVE-2015-3190

Back to search

CVE-2015-3190

Published: May 25, 2017

Modified: Aug 6, 2024

PUBLISHED

Description

With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter.

VendorProductVersions

Pivotal

Cloud Foundry

affected
Runtime cf-release versions v209 or earlier
affected
UAA Standalone versions 2.2.6 or earlier
affected
Runtime 1.4.5 or earlier

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now