CVE-2017-8044
MEDIUMSingle Sign-On for PCF 1.3.x < 1.3.4 and 1.4.x < 1.4.3 - Cross-Site Scripting via Query Parameters
Title source: llmDescription
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2017-8044
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/100618
Scores
CVSS v3
6.1
EPSS
0.0020
EPSS Percentile
41.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (6)
n/a/Single Sign-On for PCF 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3
Single Sign-On for PCF 1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3
vmware/single_sign-on_for_pivotal_cloud_foundry
1.3.0
vmware/single_sign-on_for_pivotal_cloud_foundry
1.3.2
vmware/single_sign-on_for_pivotal_cloud_foundry
1.3.3
vmware/single_sign-on_for_pivotal_cloud_foundry
1.4.1
vmware/single_sign-on_for_pivotal_cloud_foundry
1.4.2
Published
Nov 27, 2017
Tracked Since
Feb 18, 2026