CVE-2015-3190
Summary
| CVE | CVE-2015-3190 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-05-25 17:29:00 UTC |
| Updated | 2021-08-25 20:39:00 UTC |
| Description | With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter. |
Risk And Classification
Problem Types: CWE-601
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudfoundry | Cf-release | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Elastic Runtime | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Elastic Runtime Cf Release | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Uaa | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2015-3190 - Open redirect on Login | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.