PT-2017-8327 · Cloud Foundry+1 · Login-Server+3

Publicado

2017-05-25

·

Atualizado

2022-05-13

·

CVE-2016-3084

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry versions prior to v236 UAA versions prior to v3.3.0 UAA versions prior to v10 Login-server all versions Pivotal Elastic Runtime versions prior to 1.7.2
Description The UAA reset password flow is vulnerable to a brute force attack due to multiple active codes at a given time. This issue is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
Recommendations For Cloud Foundry versions prior to v236, update to a version later than v236. For UAA versions prior to v3.3.0, update to a version later than v3.3.0. For UAA versions prior to v10, update to a version later than v10. For Login-server all versions, consider disabling the UAA internal user store for authentication until a patch is available. For Pivotal Elastic Runtime versions prior to 1.7.2, update to a version later than 1.7.2.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-3084
GHSA-FM5C-2RWC-887W

Produtos afetados

Cloud Foundry
Login-Server
Pivotal Elastic Runtime
Uaa