Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgjc-gc7g-p2c6

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Cloud Foundry UAA Privilege Escalation

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. A vulnerability has been identified with the groups endpoint in UAA allowing users to elevate their privileges.

Пакеты

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 2.0.0, < 2.7.4.14

2.7.4.14

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.6.8

3.6.8

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 3.7.0, < 3.9.10

3.9.10

Наименование

org.cloudfoundry.identity:cloudfoundry-identity-server

maven
Затронутые версииВерсия исправления

>= 3.10.0, < 3.15.0

3.15.0

EPSS

Процентиль: 54%
0.00311
Низкий

8.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.8
nvd
больше 8 лет назад

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. A vulnerability has been identified with the groups endpoint in UAA allowing users to elevate their privileges.

EPSS

Процентиль: 54%
0.00311
Низкий

8.8 High

CVSS3

Дефекты

CWE-269