Vulnerability Description
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Cloud Foundry Uaa | < 4.7.5 |
| Pivotal Software | Cloud Foundry Uaa-Release | < 52.9 |
Related Weaknesses (CWE)
References
- https://www.cloudfoundry.org/blog/cve-2018-11041/Third Party Advisory
- https://www.cloudfoundry.org/blog/cve-2018-11041/Third Party Advisory
FAQ
What is CVE-2018-11041?
CVE-2018-11041 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL...
How severe is CVE-2018-11041?
CVE-2018-11041 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11041?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Cloud Foundry Uaa, Pivotal Software Cloud Foundry Uaa-Release.