First published: Thu Jun 21 2018(Updated: )
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Cloud Foundry Uaa | >4.6.0<4.7.5 | |
Pivotal Software Cloud Foundry Uaa-release | >48<52.9 | |
Pivotal Software Cloud Foundry Uaa | >4.7.5<4.10.1 | |
Pivotal Software Cloud Foundry Uaa-release | >52.9<55.1 | |
Pivotal Software Cloud Foundry Uaa | >4.10.1<4.19.0 | |
Pivotal Software Cloud Foundry Uaa-release | >55.1<60 | |
maven/org.cloudfoundry.identity:cloudfoundry-identity-server | >=4.13.0<4.19.0 | 4.19.0 |
maven/org.cloudfoundry.identity:cloudfoundry-identity-server | >=4.11.0<4.12.3 | 4.12.3 |
maven/org.cloudfoundry.identity:cloudfoundry-identity-server | >=4.8.0<4.10.1 | 4.10.1 |
maven/org.cloudfoundry.identity:cloudfoundry-identity-server | <4.7.5 | 4.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11041 is a vulnerability in Cloud Foundry UAA that allows open redirects on the login page.
CVE-2018-11041 has a severity value of 6.1, which is considered medium.
CVE-2018-11041 affects Cloud Foundry UAA versions later than 4.6.0 and prior to 4.19.0 (except 4.10.1 and 4.7.5) and uaa-release versions later than v48 and prior to v60 (except v55.1 and v52.9).
CVE-2018-11041 exploits the lack of validation of redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects.
To fix CVE-2018-11041, update your Cloud Foundry UAA installation to version 4.19.0 or above (or 4.10.1 and 4.7.5) and uaa-release to version v60 or above (or v55.1 and v52.9).