First published: Sun Sep 18 2016(Updated: )
Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Elastic Runtime | <=1.6.29 | |
Pivotal Elastic Runtime | =1.7.0 | |
Pivotal Elastic Runtime | =1.7.1 | |
Pivotal Elastic Runtime | =1.7.2 | |
Pivotal Elastic Runtime | =1.7.3 | |
Pivotal Elastic Runtime | =1.7.4 | |
Pivotal Elastic Runtime | =1.7.5 | |
Pivotal Elastic Runtime | =1.7.6 | |
Pivotal Elastic Runtime | =1.7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0928 is classified as a moderate severity vulnerability due to its potential for phishing attacks.
To fix CVE-2016-0928, upgrade Pivotal Cloud Foundry Elastic Runtime to version 1.6.30 or 1.7.8 or later.
CVE-2016-0928 affects Pivotal Cloud Foundry Elastic Runtime versions prior to 1.6.30 and 1.7.x versions before 1.7.8.
Yes, CVE-2016-0928 can be exploited by remote attackers to redirect users to arbitrary websites.
The impact of CVE-2016-0928 includes the potential for phishing attacks by redirecting users to malicious sites.