PT-2018-11292 · Cloud Foundry Foundation · Cloud Foundry Uaa
Publicado
2018-05-15
·
Atualizado
2022-05-13
·
CVE-2018-1262
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Foundation UAA versions 4.12.X through 4.13.X
Description
The issue allows for privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.
Recommendations
For Cloud Foundry Foundation UAA versions 4.12.X through 4.13.X, consider restricting the ability to configure zones to issue impersonating tokens until a fix is available. As a temporary workaround, limit the privileges granted to tokens issued for offline validation to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cloud Foundry Uaa