PT-2019-16718 · Cloud Foundry · Cloud Foundry Uaa
Published
2019-04-25
·
Updated
2019-10-09
·
CVE-2019-3788
CVSS v3.1
8.7
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry UAA Release versions prior to 71.0
Description
The issue allows clients to be configured with an insecure redirect uri. A remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim if a UAA client was configured with a wildcard in the redirect uri's subdomain.
Recommendations
For versions prior to 71.0, update to version 71.0 or later to resolve the issue. As a temporary workaround, consider restricting the use of wildcard subdomains in redirect uris to minimize the risk of exploitation.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry Uaa