"TITLE":"UAA - Login app subject to clickjacking attack"
},
"source":{
"discovery":"UNKNOWN"
},
"affects":{
"vendor":{
"vendor_data":[
{
"product":{
"product_data":[
{
"product_name":"UAA Release (OSS)",
"version":{
"version_data":[
{
"affected":"<",
"version_name":"All",
"version_value":"v73.4.0"
}
]
}
}
]
},
"vendor_name":"Cloud Foundry"
}
]
}
},
"description":{
"description_data":[
{
"lang":"eng",
"value":"Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites."
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-284: Improper Access Control - Generic"