CVE-2016-0781

Source
https://cve.org/CVERecord?id=CVE-2016-0781
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0781.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-0781
Published
2017-05-25T17:29:00.553Z
Modified
2026-04-10T03:45:56.815363Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.

References

Affected packages

Git / github.com/cloudfoundry/cf-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/cf-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "208"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "209"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "210"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "211"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "212"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "213"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "214"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "215"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "217"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "218"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "219"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "220"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "221"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "222"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "223"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "224"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "225"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "226"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "227"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "228"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "229"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "230"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "231"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "241"
        }
    ]
}
Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "1.6.5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.7.4.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.0.1"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.1.0"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.2.0"
        }
    ]
}
Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "3"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "4"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "5"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "6"
        },
        {
            "introduced": "0"
        },
        {
            "last_affected": "7"
        }
    ]
}

Affected versions

Other
-
lenient_hybrid_flow
list
log
scotty_09012012
travis-success-1475
travis-success-1478
travis-success-1497
v100
v102
v103
v104
v105
v109
v119
v132
v133
v134
v135
v136
v137
v140
v143
v156
v157
v161
v170
v183
v2
v205
v208
v209
v210
v211
v212
v213
v214
v215
v217
v218
v219
v220
v221
v222
v223
v224
v225
v226
v227
v228
v229
v230
v231
v241
v3
v4
v5
v6
v7
v99
works-for-us
1.*
1.0.1
1.0.3
1.1
1.1.1
1.1.2
1.10
1.11
1.2.0
1.2.6
1.4.0
1.4.1
1.4.2
1.4.3
1.4.5
1.4.6
1.4.7
1.5.0
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1
2.*
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.2.4.1
2.2.5
2.2.6
2.3.0
2.3.1
2.3.1.1
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.0.1
2.7.0.2
2.7.0.3
2.7.1
2.7.2
2.7.3
2.7.4
2.7.4.1
3.*
3.0.0
3.0.1
3.1.0
3.2.0
rc145.*
rc145.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0781.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "216"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.6"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.7"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.8"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.9"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.10"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.11"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.12"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.13"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.14"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.15"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.16"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.17"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.18"
            }
        ]
    },
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "1.6.19"
            }
        ]
    }
]