CVE-2019-3794: UAA - Login app subject to clickjacking attack
Published Jul 18, 2019
·Updated
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
Affected Software
1 affected component
Pivotal Software Cloud Foundry Uaa<73.4.0
Event History
Jul 18, 2019
CVE Published
via MITRE·03:47 PM
Data Sourced
via MITRE·03:47 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Cloud Foundry UAA vulnerability?
The vulnerability ID for this Cloud Foundry UAA vulnerability is CVE-2019-3794.
2
What is the severity level of CVE-2019-3794?
The severity level of CVE-2019-3794 is medium (5.4).
3
What is the description of CVE-2019-3794?
CVE-2019-3794 is a vulnerability in Cloud Foundry UAA that allows remote users to perform clickjacking attacks on UAA's frontend sites.
4
Which version of Cloud Foundry UAA is affected by CVE-2019-3794?
Versions of Cloud Foundry UAA prior to v73.4.0 are affected by CVE-2019-3794.
5
Is there a fix available for CVE-2019-3794?
Yes, updating Cloud Foundry UAA to version 73.4.0 or later will fix the vulnerability.