Логотип exploitDog
bind:CVE-2018-15754
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-15754

Количество 2

Количество 2

nvd логотип

CVE-2018-15754

около 7 лет назад

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-6c8m-9r93-f9rp

больше 3 лет назад

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-15754

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

CVSS3: 4.2
0%
Низкий
около 7 лет назад
github логотип
GHSA-6c8m-9r93-f9rp

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу