CVE-2017-8041: XSS
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8041?
CVE-2017-8041 is rated as a medium severity vulnerability due to its potential for XSS exploitation.
How do I fix CVE-2017-8041?
To fix CVE-2017-8041, upgrade to Single Sign-On for Pivotal Cloud Foundry version 1.3.4 or 1.4.3 or later.
What type of attack can be executed using CVE-2017-8041?
CVE-2017-8041 allows an attacker to execute a cross-site scripting (XSS) attack on specific Single Sign-On service UI pages.
Which versions of Pivotal Cloud Foundry are affected by CVE-2017-8041?
CVE-2017-8041 affects Single Sign-On for Pivotal Cloud Foundry versions 1.3.0 to 1.3.3 and 1.4.0 to 1.4.2.
Where can I find more information about CVE-2017-8041?
Detailed information about CVE-2017-8041 can be found in the official security advisory from Pivotal.