PT-2017-18085 · Pivotal · Single Sign-On For Pivotal Cloud Foundry
Publicado
2017-09-09
·
Atualizado
2021-08-12
·
CVE-2017-8040
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Single Sign-On for Pivotal Cloud Foundry (PCF) versions 1.3.x prior to 1.3.4
Single Sign-On for Pivotal Cloud Foundry (PCF) versions 1.4.x prior to 1.4.3
Description
An XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard, allowing privileged users to upload malformed XML. This can lead to exposure of data on the Single Sign-On service broker file system.
Recommendations
For versions 1.3.x prior to 1.3.4, update to version 1.3.4 or later.
For versions 1.4.x prior to 1.4.3, update to version 1.4.3 or later.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Single Sign-On For Pivotal Cloud Foundry