8.8
CVSSv3

CVE-2020-5402

Published: 27/02/2020 Updated: 03/03/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In Cloud Foundry UAA, versions before 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloudfoundry cf-deployment

cloudfoundry user account and authentication