Vmware Single Sign-On For Pivotal Cloud Foundry vulnerabilities
3 known vulnerabilities affecting vmware/single_sign-on_for_pivotal_cloud_foundry.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2017-8044MEDIUMCVSS 6.1v1.3.0v1.3.2+3 more2017-11-27
CVE-2017-8044 [MEDIUM] CWE-79 CVE-2017-8044: In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3),
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
nvd
CVE-2017-8040MEDIUMCVSS 6.5v1.3.0v1.3.2+5 more2017-09-09
CVE-2017-8040 [MEDIUM] CWE-611 CVE-2017-8040: In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions p
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, an XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard. Privileged users can in some cases upload malformed XML leading to exposure of data on the Single Sign-On service broker file system.
nvd
CVE-2017-8041MEDIUMCVSS 6.1v1.3.0v1.3.2+5 more2017-09-09
CVE-2017-8041 [MEDIUM] CWE-79 CVE-2017-8041: In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions p
In Single Sign-On for Pivotal Cloud Foundry (PCF) 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3, a user can execute a XSS attack on certain Single Sign-On service UI pages by inputting code in the text field for an organization name.
nvd