CVE-2021-22098
MEDIUMCloudfoundry Cf-deployment < 16.20.0 - Open Redirect
Title source: ruleDescription
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_misc
https://www.cloudfoundry.org/blog/cve-2021-22098-open-redirect-vulnerability-in-uaa-server/
Scores
CVSS v3
6.1
EPSS
0.0071
EPSS Percentile
48.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-601
Status
published
Products (2)
cloudfoundry/cf-deployment
< 16.20.0
cloudfoundry/user_account_and_authentication
< 75.5.0
Published
Aug 11, 2021
Tracked Since
Feb 18, 2026