Beveiligingsadvies

CVE-2019-3788

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2019-04-25 20:17:37
Laatst bijgewerkt 2024-09-16 22:02:12
Toegewezen door dell
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.