Total vulnerabilities in the database
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites.
Software | From | Fixed in |
---|---|---|
cloudfoundry / user_account_and_authentication | - | 75.5.0 |
cloudfoundry / cf-deployment | - | 16.20.0 |