VulnerabilityModified
CVE-2017-8044
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
MEDIUM 6.1EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- vmware/single sign-on for pivotal cloud foundry
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/100618Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2017-8044Vendor Advisory
- http://www.securityfocus.com/bid/100618Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2017-8044Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.