CVE-2015-5173: Infoleak
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5173?
CVE-2015-5173 is classified as a medium severity vulnerability.
How do I fix CVE-2015-5173?
To fix CVE-2015-5173, upgrade to Cloud Foundry Runtime cf-release version 216 or later, UAA version 2.5.2 or later, or Pivotal Cloud Foundry Elastic Runtime version 1.7.0 or later.
What is the impact of CVE-2015-5173?
The impact of CVE-2015-5173 allows attackers to exploit unspecified vectors involving emails with password recovery links.
Which versions are affected by CVE-2015-5173?
Versions affected by CVE-2015-5173 include cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry Elastic Runtime before 1.7.0.
Who should be concerned about CVE-2015-5173?
Organizations using the affected versions of Cloud Foundry runtime components should be concerned about CVE-2015-5173.