CVE-2016-0781: XSS
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0781?
CVE-2016-0781 is classified as a high severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2016-0781?
To fix CVE-2016-0781, upgrade to the recommended patched version of Cloud Foundry UAA or Pivotal Elastic Runtime.
Which versions are affected by CVE-2016-0781?
CVE-2016-0781 affects Cloud Foundry UAA versions up to 2.7.4.1 and Pivotal Elastic Runtime versions prior to 1.6.20.
What type of vulnerability is CVE-2016-0781?
CVE-2016-0781 is an XSS (Cross-Site Scripting) vulnerability that can be exploited via malicious JavaScript.
Is there a workaround for CVE-2016-0781?
Currently, the best recommendation for CVE-2016-0781 is to apply the necessary updates or patches rather than relying on a workaround.