Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
2016-09-18T02:59:08.997
2025-04-12T10:46:40.837
Deferred
CVSSv3.0: 7.4 (HIGH)
AV:N/AC:M/Au:N/C:P/I:P/A:N
8.6
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal | cloud_foundry_elastic_runtime | ≤ 1.6.29 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.0 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.1 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.2 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.3 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.4 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.5 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.6 | Yes |
Application | pivotal | cloud_foundry_elastic_runtime | 1.7.7 | Yes |