Back

HIGH

UAA fails to check the state parameter when authenticating with external IDPs

Published Feb 27, 2020

Description

In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Feb 27, 2020
Updated Sep 16, 2024
Reserved Jan 3, 2020
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner pivotal
Published Feb 27, 2020
Updated Sep 16, 2024
Exploited since n/a
EUVD-2020-26581