Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2rm2-vwh2-fp52

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

EPSS

Процентиль: 52%
0.00294
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307

Связанные уязвимости

CVSS3: 6.6
nvd
больше 7 лет назад

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

EPSS

Процентиль: 52%
0.00294
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-307