PT-2018-11292 · Cloud Foundry Foundation · Cloud Foundry Uaa
Published
2018-05-15
·
Updated
2022-05-13
·
CVE-2018-1262
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Foundation UAA versions 4.12.X through 4.13.X
Description
The issue allows for privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.
Recommendations
For Cloud Foundry Foundation UAA versions 4.12.X through 4.13.X, consider restricting the ability to configure zones to issue impersonating tokens until a fix is available. As a temporary workaround, limit the privileges granted to tokens issued for offline validation to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Foundry Uaa