Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8v97-gv3g-32rf

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

UAA privilege escalation across identity zones

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

Пакеты

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 4.12.0, < 4.12.2

4.12.2

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 4.13.0, < 4.13.4

4.13.4

EPSS

Процентиль: 60%
0.00392
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
больше 7 лет назад

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

EPSS

Процентиль: 60%
0.00392
Низкий

7.2 High

CVSS3