An open redirect vulnerability has been detected with some Pivotal Cloud Foundry Elastic Runtime components. Users of affected versions should apply the following mitigation: Upgrade PCF Elastic Runtime 1.8.x versions to 1.8.12 or later. Upgrade PCF Ops Manager 1.7.x versions to 1.7.18 or later and 1.8.x versions to 1.8.10 or later.
A web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a Redirect. This simplifies phishing attacks.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cloud_foundry_ops_manager | Pivotal_software | 1.7.0 (including) | 1.7.0 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.1 (including) | 1.7.1 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.2 (including) | 1.7.2 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.3 (including) | 1.7.3 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.4 (including) | 1.7.4 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.5 (including) | 1.7.5 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.6 (including) | 1.7.6 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.7 (including) | 1.7.7 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.8 (including) | 1.7.8 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.9 (including) | 1.7.9 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.10 (including) | 1.7.10 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.11 (including) | 1.7.11 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.12 (including) | 1.7.12 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.13 (including) | 1.7.13 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.14 (including) | 1.7.14 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.15 (including) | 1.7.15 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.16 (including) | 1.7.16 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.17 (including) | 1.7.17 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.7.18 (including) | 1.7.18 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.0 (including) | 1.8.0 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.1 (including) | 1.8.1 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.2 (including) | 1.8.2 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.3 (including) | 1.8.3 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.4 (including) | 1.8.4 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.5 (including) | 1.8.5 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.6 (including) | 1.8.6 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.7 (including) | 1.8.7 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.8 (including) | 1.8.8 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.9 (including) | 1.8.9 (including) |
Cloud_foundry_ops_manager | Pivotal_software | 1.8.10 (including) | 1.8.10 (including) |