CVE-2017-8044: VMware Single Sign-On For Pivotal Cloud Foundry
Medium severity, CVSS 6.1. EPSS: 0.9% chance of exploitation in the next 30 days.
In Pivotal Single Sign-On for PCF (1.3.x versions prior to 1.3.4 and 1.4.x versions prior to 1.4.3), certain pages allow code to be injected into the DOM environment through query parameters, leading to XSS attacks.
Affected products
- VMware Single Sign-On For Pivotal Cloud Foundry: version 1.3.0 only; version 1.3.2 only; version 1.3.3 only; version 1.4.1 only; version 1.4.2 only
Published 2017-11-27. Last modified 2026-06-17.