CVE-2015-3191: Cloudfoundry Cf-Release
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the change_email form in UAA is vulnerable to a CSRF attack. This allows an attacker to trigger an e-mail change for a user logged into a cloud foundry instance via a malicious link on a attacker controlled site. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
Affected products
- Cloudfoundry Cf-Release: up to and including 209
- Pivotal Software Cloud Foundry Elastic Runtime: up to and including 1.4.5
- Pivotal Software Cloud Foundry Uaa: up to and including 2.2.6
Published 2017-05-25. Last modified 2026-06-17.