Описание
Cloud Foundry Runtime Cross-Site Request Forgery vulnerability
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2015-5170
- https://github.com/cloudfoundry/uaa/commit/41dba9d81dbdf24ede4fb9719de28b1b88b3e1b4
- https://github.com/cloudfoundry/uaa/commit/a54f3fb8225ef7d5021ca7d4fb52bef1e884568e
- https://github.com/cloudfoundry/uaa/commit/bdb1a39a1e72f615f2e7a429a896a11e7ee5ec17
- https://pivotal.io/security/cve-2015-5170-5173
- http://www.securityfocus.com/bid/101579
Пакеты
Наименование
org.cloudfoundry.identity:cloudfoundry-identity-server
maven
Затронутые версииВерсия исправления
< 2.5.2
2.5.2
Связанные уязвимости
CVSS3: 8.8
nvd
больше 8 лет назад
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.