CVE-2020-5402: UAA fails to check the state parameter when authenticating with external IDPs
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cloud Foundry UAAto a version that resolves this vulnerability.Fixed in 74.14.0
Event History
Frequently Asked Questions
What is the vulnerability ID for this Cloud Foundry UAA vulnerability?
The vulnerability ID for this Cloud Foundry UAA vulnerability is CVE-2020-5402.
What is the severity of CVE-2020-5402?
The severity of CVE-2020-5402 is high with a severity value of 8.8.
What is the affected software for CVE-2020-5402?
The affected software for CVE-2020-5402 is Cloud Foundry UAA versions prior to 74.14.0.
What is the description of CVE-2020-5402?
CVE-2020-5402 is a CSRF vulnerability in Cloud Foundry UAA, versions prior to 74.14.0, due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
Is there a fix available for CVE-2020-5402?
Yes, a fix is available for CVE-2020-5402. It is recommended to update to Cloud Foundry UAA version 74.14.0 or later.