← back
CVE-2020-5402highCWE-352

UAA fails to check the state parameter when authenticating with external IDPs

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Cloud Foundry · UAA