CVE-2018-11041

Source
https://cve.org/CVERecord?id=CVE-2018-11041
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11041.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-11041
Aliases
Published
2018-06-25T15:29:00.410Z
Modified
2026-07-08T05:50:46.152833011Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote attacker can craft a malicious link that, when clicked, will redirect users to arbitrary websites after a successful login attempt.

Database specific
{
    "unresolved_ranges": [
        {
            "source": "CPE_RANGE",
            "cpes": [
                "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*"
            ],
            "vendor_product": "pivotal_software:cloud_foundry_uaa",
            "extracted_events": [
                {
                    "fixed": "4.7.5"
                },
                {
                    "fixed": "4.7.5"
                }
            ]
        }
    ]
}
References

Affected packages

Git / github.com/cloudfoundry/uaa

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "4.7.5"
        },
        {
            "fixed": "4.10.1"
        },
        {
            "fixed": "4.19.0"
        }
    ]
}

Affected versions

1.*
1.0.1
1.0.3
1.1
1.1.1
1.1.2
1.2.0
1.2.6
1.4.0
1.4.1
1.4.2
1.4.3
1.4.5
1.4.6
1.4.7
1.5.0
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.1
1.6.2
1.8.0
3.*
3.10.0
3.11.0
3.12.0
3.13.0
3.14.0
3.15.0
3.16.0
3.8.0
3.9.0
3.9.1
3.9.2
3.9.3
4.*
4.0.0
4.1.0
4.10.0
4.11.0
4.12.0
4.15.0
4.16.0
4.17.0
4.18.0
4.2.0
4.3.0
4.4.0
4.5.0
4.6.0
4.6.1
4.7.0
4.7.1
4.7.3
4.9.0
releases/4.*
releases/4.15.0
Other
travis-success-1475
travis-success-1478
travis-success-1497

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11041.json"

Git / github.com/cloudfoundry/uaa-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Fixed
Database specific
{
    "cpe": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "52.9"
        },
        {
            "fixed": "55.1"
        },
        {
            "fixed": "60"
        }
    ]
}

Affected versions

Other
ci-upgrade
v10
v11
v12
v14
v15
v16
v17
v18
v19
v2
v20
v21
v22
v23
v24
v25
v26
v27
v3
v31
v52
v53
v55
v56
v57
v58
v59
v6
v7
v8
v9
v12.*
v12.3
v52.*
v52.1
v52.2
v52.4
v52.5
v52.6
v52.7
v52.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11041.json"