CVE-2017-4963Session Fixation in Software Cloud Foundry Cf-release

CWE-384Session Fixation3 documents3 sources
Severity
8.1HIGHNVD
EPSS
0.4%
top 40.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 13
Latest updateMay 14

Description

An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-v3fx-g84p-g838: An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v22022-05-14
CVEList
CVE-2017-4963: An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v22017-06-13
CVE-2017-4963 — Session Fixation | cvebase