CVE-2015-5170 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Cloud Foundry Runtime (cf-release before 216), UAA (before 2.5.2), and Pivotal Cloud Foundry (PCF) Elastic Runtime (before 1.7.0). This flaw allows remote attackers to log users into arbitrary accounts on PWS due to missing CSRF checks. With a CVSS score of 8.8 (High), it presents a significant risk with network-based attacks, low attack complexity, and high impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, suggesting it is not widely targeted.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 216CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | ||
< 1.7.0CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:* | ||
< 2.5.2CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.