CRITICAL
UAA Privilege Escalation
Published Nov 19, 2018
9.9
CRITICALCVSS 3.0
EPSS 1.71%
Description
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
Affected products
-
- Version all versionsStatusaffectedConstraints<4.23.0
- Version
-
- Version all versionsStatusaffectedConstraints<64.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Cloud Foundry | UAA | n/a |
| ||||||
| Cloud Foundry | UAA Release | n/a |
|
OR
- < 4.23.0
- < 64.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (0)
No CWE recorded.
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-1946 Advisory
- https://github.com/advisories/GHSA-292x-hjr8-226f Advisory
- https://github.com/cloudfoundry/uaa/commit/3f0730a015d10166de23b7e036743c185f0576a6
- https://github.com/cloudfoundry/uaa/commit/95b7d9e7fae534a362b98de1df5bf501cd52c481
- https://nvd.nist.gov/vuln/detail/CVE-2018-15761
- https://www.cloudfoundry.org/blog/cve-2018-15761 x_refsource_CONFIRMVendor Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner dell
Published Nov 19, 2018
Updated Sep 17, 2024
Reserved Aug 23, 2018
Link CVE-2018-15761
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-1946 GHSA-292X-HJR8-226F Assigner dell
Published Nov 19, 2018
Updated Sep 17, 2024
Exploited since n/a
Link EUVD-2022-1946