Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown
UAA redirect-uri allows wildcard in the subdomain
Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.
0