CVE-2015-5173

EUVD-2015-5176
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
cloudfoundrycf-release
𝑥
< 216
pivotal_softwarecloud_foundry_elastic_runtime
𝑥
< 1.7.0
pivotal_softwarecloud_foundry_uaa
𝑥
< 2.5.2
𝑥
= Vulnerable software versions