Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
BID:109315
Info
Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
| Bugtraq ID: | 109315 |
| Class: | Design Error |
| CVE: |
CVE-2019-3794 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 09 2019 12:00AM |
| Updated: | Jul 09 2019 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Cloud Foundry UAA 73.3 Cloud Foundry UAA 73.0 Cloud Foundry UAA 72.0 Cloud Foundry UAA 64.0 Cloud Foundry UAA 63.0 |
| Not Vulnerable: |
Cloud Foundry UAA 73.4 |
Discussion
Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
Cloud Foundry UAA Release is prone to a clickjacking vulnerability.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
Cloud Foundry UAA Release (OSS) versions prior to 73.4.0 are vulnerable.
Cloud Foundry UAA Release is prone to a clickjacking vulnerability.
Successful exploits will allow an attacker to compromise the affected application or obtain sensitive information. Other attacks are also possible.
Cloud Foundry UAA Release (OSS) versions prior to 73.4.0 are vulnerable.
Exploit / POC
Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
Attackers can exploit these issues using browser or readily available tools.
Attackers can exploit these issues using browser or readily available tools.
Solution / Fix
Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cloud Foundry UAA Release CVE-2019-3794 Clickjacking Vulnerability
References:
References:
- Cloud Foundry Home Page (Cloud Foundry)
- uaa-release (Github)
- CVE-2019-3794: UAA �?? Login app subject to clickjacking attack (Cloud Foundry)