CVE-2015-5170
HIGH8.8EPSS 0.31%Cloud Foundry Runtime Cross-Site Request Forgery vulnerability
發布日:2022/5/13修改日:2024/2/28
描述
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
受影響套件(1)
- Maven/org.cloudfoundry.identity:cloudfoundry-identity-serverfrom 0, < 2.5.2
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
參考連結(7)
- ADVISORYhttps://nvd.nist.gov/vuln/detail/CVE-2015-5170
- PATCHhttps://github.com/cloudfoundry/uaa
- WEBhttps://github.com/cloudfoundry/uaa/commit/41dba9d81dbdf24ede4fb9719de28b1b88b3e1b4
- WEBhttps://github.com/cloudfoundry/uaa/commit/a54f3fb8225ef7d5021ca7d4fb52bef1e884568e
- WEBhttps://github.com/cloudfoundry/uaa/commit/bdb1a39a1e72f615f2e7a429a896a11e7ee5ec17
- WEBhttps://pivotal.io/security/cve-2015-5170-5173
- WEBhttp://www.securityfocus.com/bid/101579