{"id":"GHSA-j97q-9xp9-g5fx","summary":"Pivotal Cloud Foundry UAA XSS on UAA OpenID Connect check session iframe endpoint","details":"An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.","aliases":["CVE-2018-1190"],"modified":"2024-03-01T23:56:53.602224Z","published":"2022-05-13T01:10:01Z","database_specific":{"nvd_published_at":"2018-01-04T06:29:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-03-01T23:42:54Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1190"},{"type":"WEB","url":"https://github.com/cloudfoundry/uaa/commit/96fe26711f8f8855d2994a531447f730afd61844"},{"type":"PACKAGE","url":"https://github.com/cloudfoundry/uaa"},{"type":"WEB","url":"https://web.archive.org/web/20200227133214/http://www.securityfocus.com/bid/102427"},{"type":"WEB","url":"https://www.cloudfoundry.org/cve-2018-1190"}],"affected":[{"package":{"name":"org.cloudfoundry.identity:cloudfoundry-identity-server","ecosystem":"Maven","purl":"pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.20.2"}]}],"versions":["3.0.0","3.0.1","3.1.0","3.10.0","3.12.0","3.13.0","3.15.0","3.16.0","3.18.0","3.19.0","3.2.0","3.2.1","3.20.0","3.3.0","3.3.0.1","3.3.0.2","3.3.0.3","3.3.0.4","3.3.0.5","3.4.0","3.4.2","3.4.3","3.4.4","3.4.5","3.5.0","3.6.0","3.7.0","3.7.3","3.8.0","3.9.0","3.9.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j97q-9xp9-g5fx/GHSA-j97q-9xp9-g5fx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}