CVE-2018-11041 describes an open redirect vulnerability in Cloud Foundry UAA, affecting versions later than 4.6.0 and prior to 4.19.0 (excluding 4.10.1 and 4.7.5), and uaa-release versions later than v48 and prior to v60 (excluding v55.1 and v52.9). This flaw allows a remote attacker to craft a malicious link that redirects users to arbitrary websites after a successful login. Rated Medium (CVSS 6.1), the vulnerability requires user interaction (UI:R) and can lead to low impact on confidentiality and integrity (C:L/I:L). There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
> 4.6.0, < 4.7.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* | ||
> 48, < 52.9CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* | ||
> 4.7.5, < 4.10.1CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* | ||
> 52.9, < 55.1CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:* | ||
> 4.10.1, < 4.19.0CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.