Vulnerability Description
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Single Sign-On For Pivotal Cloud Foundry | 1.3.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/100618Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2017-8044Vendor Advisory
- http://www.securityfocus.com/bid/100618Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2017-8044Vendor Advisory
FAQ
What is CVE-2017-8044?
CVE-2017-8044 is a vulnerability with a CVSS score of 6.1 (MEDIUM). In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading ...
How severe is CVE-2017-8044?
CVE-2017-8044 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-8044?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Single Sign-On For Pivotal Cloud Foundry.