PT-2023-17693 · Cloud Foundry · Cloud Foundry Uaa

Florian Tack

·

Published

2023-03-28

·

Updated

2023-04-06

·

CVE-2023-20903

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry UAA (affected versions not specified)
Description The issue is related to UAA refresh tokens and external identity providers. When an external identity provider linked to the UAA is deactivated, the UAA fails to reject refresh tokens issued on behalf of users from that identity provider. As a result, clients with such refresh tokens can continue to access Cloud Foundry resources until the refresh token expires, which defaults to 30 days.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficient Session Expiration

Weakness Enumeration

Related Identifiers

CVE-2023-20903

Affected Products

Cloud Foundry Uaa