PT-2021-14841 · Uaa · Uaa

Klaus Kiefer

·

Published

2021-07-22

·

Updated

2021-08-04

·

CVE-2021-22001

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions UAA versions prior to 75.3.0
Description The issue concerns the revelation of sensitive information, such as the relaying secret of the provider, in response to a deletion request of an identity provider (IdP) of type "oauth 1.0" sent to the UAA server.
Recommendations For versions prior to 75.3.0, update to version 75.3.0 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22001

Affected Products

Uaa