First published: Thu Feb 27 2020(Updated: )
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
Credit: security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Cf-deployment | <12.33.0 | |
Cloudfoundry User Account And Authentication | <74.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Cloud Foundry UAA vulnerability is CVE-2020-5402.
The severity of CVE-2020-5402 is high with a severity value of 8.8.
The affected software for CVE-2020-5402 is Cloud Foundry UAA versions prior to 74.14.0.
CVE-2020-5402 is a CSRF vulnerability in Cloud Foundry UAA, versions prior to 74.14.0, due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
Yes, a fix is available for CVE-2020-5402. It is recommended to update to Cloud Foundry UAA version 74.14.0 or later.