{"id":"CVE-2016-0781","details":"The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.","modified":"2026-08-27T03:45:07.027997242Z","published":"2017-05-25T17:29:00.553Z","database_specific":{"unresolved_ranges":[{"vendor_product":"pivotal_software:cloud_foundry","cpes":["cpe:2.3:a:pivotal_software:cloud_foundry:216:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"216"},{"last_affected":"216"}],"source":"CPE_STRING"},{"cpes":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.10:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.11:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.12:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.13:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.14:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.15:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.16:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.17:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.18:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.19:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.6:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.7:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.8:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.9:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.6.0"},{"last_affected":"1.6.0"},{"introduced":"1.6.6"},{"last_affected":"1.6.6"},{"introduced":"1.6.6"},{"last_affected":"1.6.6"},{"introduced":"1.6.7"},{"last_affected":"1.6.7"},{"introduced":"1.6.7"},{"last_affected":"1.6.7"},{"introduced":"1.6.8"},{"last_affected":"1.6.8"},{"introduced":"1.6.8"},{"last_affected":"1.6.8"},{"introduced":"1.6.9"},{"last_affected":"1.6.9"},{"introduced":"1.6.9"},{"last_affected":"1.6.9"},{"introduced":"1.6.10"},{"last_affected":"1.6.10"},{"introduced":"1.6.10"},{"last_affected":"1.6.10"},{"introduced":"1.6.11"},{"last_affected":"1.6.11"},{"introduced":"1.6.11"},{"last_affected":"1.6.11"},{"introduced":"1.6.12"},{"last_affected":"1.6.12"},{"introduced":"1.6.12"},{"last_affected":"1.6.12"},{"introduced":"1.6.13"},{"last_affected":"1.6.13"},{"introduced":"1.6.13"},{"last_affected":"1.6.13"},{"introduced":"1.6.14"},{"last_affected":"1.6.14"},{"introduced":"1.6.14"},{"last_affected":"1.6.14"},{"introduced":"1.6.15"},{"last_affected":"1.6.15"},{"introduced":"1.6.15"},{"last_affected":"1.6.15"},{"introduced":"1.6.16"},{"last_affected":"1.6.16"},{"introduced":"1.6.16"},{"last_affected":"1.6.16"},{"introduced":"1.6.17"},{"last_affected":"1.6.17"},{"introduced":"1.6.17"},{"last_affected":"1.6.17"},{"introduced":"1.6.18"},{"last_affected":"1.6.18"},{"introduced":"1.6.18"},{"last_affected":"1.6.18"},{"introduced":"1.6.19"},{"last_affected":"1.6.19"},{"introduced":"1.6.19"},{"last_affected":"1.6.19"}],"source":"CPE_STRING","vendor_product":"pivotal_software:cloud_foundry_elastic_runtime"}]},"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-0781"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry-attic/cf-release","events":[{"introduced":"6003f780fffc7e2e4dcf9ba76dc20a7bde65583c"},{"last_affected":"ae0aca492ca3c5c2cc00ddaf9630b36372874b56"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:pivotal_software:cloud_foundry:208:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:209:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:210:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:211:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:212:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:213:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:214:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:215:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:217:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:218:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:219:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:220:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:221:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:222:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:223:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:224:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:225:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:226:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:227:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:228:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:229:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:230:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:231:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry:241:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"208"},{"last_affected":"208"},{"introduced":"209"},{"last_affected":"209"},{"introduced":"210"},{"last_affected":"210"},{"introduced":"211"},{"last_affected":"211"},{"introduced":"212"},{"last_affected":"212"},{"introduced":"213"},{"last_affected":"213"},{"introduced":"214"},{"last_affected":"214"},{"introduced":"215"},{"last_affected":"215"},{"introduced":"217"},{"last_affected":"217"},{"introduced":"218"},{"last_affected":"218"},{"introduced":"219"},{"last_affected":"219"},{"introduced":"220"},{"last_affected":"220"},{"introduced":"221"},{"last_affected":"221"},{"introduced":"222"},{"last_affected":"222"},{"introduced":"223"},{"last_affected":"223"},{"introduced":"224"},{"last_affected":"224"},{"introduced":"225"},{"last_affected":"225"},{"introduced":"226"},{"last_affected":"226"},{"introduced":"227"},{"last_affected":"227"},{"introduced":"228"},{"last_affected":"228"},{"introduced":"229"},{"last_affected":"229"},{"introduced":"230"},{"last_affected":"230"},{"introduced":"231"},{"last_affected":"231"},{"introduced":"241"},{"last_affected":"241"}]}}],"versions":["208","209","210","211","212","213","214","215","217","218","219","220","221","222","223","224","225","226","227","228","229","230","231","241"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0781.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa","events":[{"introduced":"0"},{"last_affected":"6f4197812dcb5da43b5c6bc2bed119c7cb51a649"},{"introduced":"ae59bf11fec166fd075b1dbead2ae16effa57e3f"},{"last_affected":"769e65183c297651cdd7bedab1dff112f9d38920"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.1:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.2:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.3:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.4:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.6.5:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.0.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.0.1:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.1.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.2.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"2.7.4.1"},{"introduced":"1.6.0"},{"last_affected":"1.6.0"},{"introduced":"1.6.1"},{"last_affected":"1.6.1"},{"introduced":"1.6.2"},{"last_affected":"1.6.2"},{"introduced":"1.6.3"},{"last_affected":"1.6.3"},{"introduced":"1.6.4"},{"last_affected":"1.6.4"},{"introduced":"1.6.5"},{"last_affected":"1.6.5"},{"introduced":"3.0.0"},{"last_affected":"3.0.0"},{"introduced":"3.0.1"},{"last_affected":"3.0.1"},{"introduced":"3.1.0"},{"last_affected":"3.1.0"},{"introduced":"3.2.0"},{"last_affected":"3.2.0"}]}}],"versions":["1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","3.0.0","3.0.1","3.1.0","3.2.0","2.7.4.1","2.7.4","2.7.3","2.7.2","2.7.1","2.7.0.3","2.7.0.2","2.7.0.1","2.7.0","2.6.2","2.6.1","2.6.0","2.5.2","2.5.1","2.5.0","2.4.1","2.2.5","2.4.0","2.3.1.1","2.3.1","2.3.0","2.2.6","2.2.4.1","2.1.0","2.0.3","2.0.2","travis-success-1497","travis-success-1478","travis-success-1475","2.0.1","2.0.0","lenient_hybrid_flow","1.11","1.10","1.9.1","1.9.0","1.8.3","1.8.2","1.8.1","1.8.0","1.7.2","1.7.1","1.7.0","1.5.4.1","1.5.4","1.5.3","1.5.2.1","1.5.2","1.5.0","1.4.7","1.4.6","1.4.5","1.4.3","1.4.2","1.4.1","1.4.0","1.2.6","1.2.0","1.1.2","1.1.1","1.1","1.0.3","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0781.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa-release","events":[{"introduced":"dc291df0c1f79318317ecf588a6846dc9db315c3"},{"last_affected":"3732e7b8eccff5cd497a72d1eed1165d6dae60f1"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:2:*:*:*:*:*:*:*","cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:3:*:*:*:*:*:*:*","cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:4:*:*:*:*:*:*:*","cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:5:*:*:*:*:*:*:*","cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:6:*:*:*:*:*:*:*","cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2"},{"last_affected":"2"},{"introduced":"3"},{"last_affected":"3"},{"introduced":"4"},{"last_affected":"4"},{"introduced":"5"},{"last_affected":"5"},{"introduced":"6"},{"last_affected":"6"},{"introduced":"7"},{"last_affected":"7"}]}}],"versions":["2","3","4","5","6","7","v7","v6","v3","v2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-0781.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}