PT-2020-18458 · Cloud Foundry · Cloud Foundry Uaa

Jonathan Leitschuh

·

Published

2020-02-27

·

Updated

2020-03-03

·

CVE-2020-5402

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry UAA versions prior to 74.14.0
Description A CSRF issue exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
Recommendations For versions prior to 74.14.0, update to version 74.14.0 or later to resolve the issue.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5402

Affected Products

Cloud Foundry Uaa