Описание
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
Уязвимые конфигурации
Конфигурация 1Версия до 16.18.0 (исключая)Версия до 75.3.0 (исключая)
Одно из
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:user_account_and_authentication:*:*:*:*:*:*:*:*
EPSS
Процентиль: 55%
0.00322
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
NVD-CWE-noinfo
Связанные уязвимости
github
больше 3 лет назад
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
EPSS
Процентиль: 55%
0.00322
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
NVD-CWE-noinfo