Vulnerability Name:

CVE-2018-11041 (CCN-145414)

Assigned:2018-06-21
Published:2018-06-21
Updated:2018-08-23
Summary:Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.
CVSS v3 Severity:6.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
7.4 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N)
6.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-601
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2018-11041

Source: XF
Type: UNKNOWN
cloudfoundry-cve201811041-open-redirect(145414)

Source: CCN
Type: Cloud Foundry Blog, June 21, 2018
CVE-2018-11041: UAA open redirect

Source: CONFIRM
Type: Third Party Advisory
https://www.cloudfoundry.org/blog/cve-2018-11041/

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2018-11041

Vulnerable Configuration:Configuration 1:
  • cpe:/a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* (Version > 4.6.0 and < 4.7.5)
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* (Version > 48 and < 52.9)

  • Configuration 2:
  • cpe:/a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* (Version > 4.7.5 and < 4.10.1)
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* (Version > 52.9 and < 55.1)

  • Configuration 3:
  • cpe:/a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* (Version > 4.10.1 and < 4.19.0)
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* (Version > 55.1 and < 60)

  • Configuration CCN 1:
  • cpe:/a:pivotal_software:cloud_foundry_uaa:4.19.0:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa:4.10.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa:4.7.5:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:60:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:55.1:*:*:*:*:*:*:*
  • OR cpe:/a:pivotal_software:cloud_foundry_uaa-release:52.9:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    pivotal_software cloud foundry uaa *
    pivotal_software cloud foundry uaa-release *
    pivotal_software cloud foundry uaa *
    pivotal_software cloud foundry uaa-release *
    pivotal_software cloud foundry uaa *
    pivotal_software cloud foundry uaa-release *
    pivotal_software cloud foundry uaa 4.19.0
    pivotal_software cloud foundry uaa 4.10.1
    pivotal_software cloud foundry uaa 4.7.5
    pivotal_software cloud foundry uaa-release 60
    pivotal_software cloud foundry uaa-release 55.1
    pivotal_software cloud foundry uaa-release 52.9