Skip to main content

Vendor/product archive

pivotal_software / cloud_foundry_uaa CVEs

Beta · best-effort

32 CVEs tagged to pivotal_software / cloud_foundry_uaa5 Critical, 17 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2019-3794

Published Jul 18, 2019

Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11047

Published Jul 24, 2018

Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests t…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2