{"id":"CVE-2017-8047","details":"In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.","modified":"2026-08-27T03:47:38.791284219Z","published":"2017-10-04T01:29:03.620Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"last_affected":"0.162.0"}],"source":"CPE_RANGE","vendor_product":"pivotal:routing-release","cpes":["cpe:2.3:a:pivotal:routing-release:*:*:*:*:*:*:*:*"]}]},"references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/cve-2017-8047/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry-attic/cf-release","events":[{"introduced":"0"},{"last_affected":"0d3dff9de8a0b4bcacf025bd50dd9dcbfe9675d3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"273"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*"}}],"versions":["v273","v262","v260","v253","v249","v245","v205","v183","v170","v161","v157","v156","rc145.0","v143","works-for-us","v140","v137","v136","v135","v134","v133","v132","scotty_09012012","v119","v109","v105","v104","v103","v102","v100","v99","-","log","list"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8047.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}