Количество 2
Количество 2

CVE-2018-15761
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
GHSA-292x-hjr8-226f
Cloud Foundry UAA Privilege Escalation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2018-15761 Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges. | CVSS3: 9.9 | 1% Низкий | больше 6 лет назад |
GHSA-292x-hjr8-226f Cloud Foundry UAA Privilege Escalation | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу