Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-1190

EPSS 0.22% · P44
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2018-1190

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Pivotal Cloud Foundry Runtime cf-release、UAA和UAA bosh 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Pivotal Cloud Foundry(PCF)Runtime cf-release等都是美国Pivotal Software公司的产品。PCF是一套开源的平台即服务(PaaS)云计算平台,它提供容器调度、持续交付和自动化服务部署等功能。cf-release是PCF的一个发布版本。UAA是PCF的一个身份验证和管理服务终端。UAA bosh是一款用于统一小型和大型云软件的发布系统。 PCF cf-release、UAA和UAA bosh存在跨站脚本漏洞。远程攻击者可利用该漏洞注入任意Web脚本或HTM
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0 Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0 -

II. Public POCs for CVE-2018-1190

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2018-1190

登录查看更多情报信息。

Same Patch Batch · n/a · 2018-01-04 · 21 CVEs total

CVE-2018-5212WordPress Simple Download Monitor插件跨站脚本漏洞
CVE-2018-5220K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5219K7 Antivirus K7FWHlpr.sys文件安全漏洞
CVE-2018-5218K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5217K7 Antivirus K7Sentry.sys 安全漏洞
CVE-2018-5216Radiant CMS 跨站脚本漏洞
CVE-2018-5215Fork CMS 跨站脚本漏洞
CVE-2017-17867Inteno iopsys 安全漏洞
CVE-2018-5214WordPress Add Link to Facebook插件跨站脚本漏洞
CVE-2018-5213WordPress Simple Download Monitor插件跨站脚本漏洞
CVE-2017-18018GNU Coreutils 安全漏洞
CVE-2017-14960OpenText Document Sciences xPression xDashboard SQL注入漏洞
CVE-2014-7862ZOHO ManageEngine Desktop Central和Desktop Central MSP 权限许可和访问控制漏洞
CVE-2018-5210Samsung移动设备缓冲区错误漏洞
CVE-2018-0114Cisco node-jose open source library 数据伪造问题漏洞
CVE-2018-0104多款Cisco产品WebEx ARF player 安全漏洞
CVE-2018-0103多款Cisco产品WebEx ARF player 缓冲区错误漏洞
CVE-2017-18020Samsung移动设备安全漏洞
CVE-2017-14383Dell EMC VNX2 Operating Environment for File和VNX1 Operating Environment for File VNX Contr
CVE-2017-18019K7 Total Security 安全漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2018-1190

No comments yet


Leave a comment