CVE-2015-5170
24.10.2017, 17:29
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
Vendor | Product | Version |
---|---|---|
cloudfoundry | cf-release | 𝑥 < 216 |
pivotal_software | cloud_foundry_elastic_runtime | 𝑥 < 1.7.0 |
pivotal_software | cloud_foundry_uaa | 𝑥 < 2.5.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration