High severity8.8NVD Advisory· Published Oct 24, 2017· Updated Jun 17, 2026
CVE-2015-5170
CVE-2015-5170
Description
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.cloudfoundry.identity:cloudfoundry-identity-serverMaven | < 2.5.2 | 2.5.2 |
Affected products
4- cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*Range: <1.7.0
Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/101579nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-mpv3-g527-fqrjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2015-5170ghsaADVISORY
- pivotal.io/security/cve-2015-5170-5173nvdVendor AdvisoryWEB
- github.com/cloudfoundry/uaa/commit/41dba9d81dbdf24ede4fb9719de28b1b88b3e1b4ghsaWEB
- github.com/cloudfoundry/uaa/commit/a54f3fb8225ef7d5021ca7d4fb52bef1e884568eghsaWEB
- github.com/cloudfoundry/uaa/commit/bdb1a39a1e72f615f2e7a429a896a11e7ee5ec17ghsaWEB
News mentions
0No linked articles in our index yet.