CVE-2019-3788: UAA redirect-uri allows wildcard in the subdomain
Published Apr 25, 2019
·Updated
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.
Affected Software
1 affected component
cloudfoundry Uaa Release<71.0
Event History
Apr 25, 2019
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:29 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2019-3788.
2
What is the severity level of CVE-2019-3788?
The severity level of CVE-2019-3788 is high.
3
What software is affected by CVE-2019-3788?
Cloud Foundry UAA Release versions prior to 71.0 are affected by CVE-2019-3788.
4
How can an attacker exploit this vulnerability?
An attacker can craft a phishing link to get a UAA access code from the victim.
5
Is there a fix available for CVE-2019-3788?
Yes, the fix for CVE-2019-3788 is to update to Cloud Foundry UAA Release version 71.0 or later.