6.1
CVSSv3

CVE-2015-3190

Published: 25/05/2017 Updated: 25/08/2021
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an malicious user to insert malicious web page as a redirect parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloudfoundry cf-release

pivotal software cloud foundry elastic runtime

pivotal software cloud foundry uaa