CVE-2018-1190: Cloudfoundry Cf-Release
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID Connect check session iframe endpoint used for single logout session management.
Affected products
- Cloudfoundry Cf-Release: up to and including 269
- Pivotal Uaa: from 3.0.0, up to and including 3.20.1
- Pivotal Uaa Bosh: up to and including 44
Published 2018-01-04. Last modified 2026-06-17.