An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions prior to v24.9, 30.x versions prior to 30.2, and other versions prior to v36. Privileged users in one zone are allowed to perform a password reset for users in a different zone.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cf-release | Cloudfoundry | * | 259 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | * | 35 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.1 (including) | 13.1 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.2 (including) | 13.2 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.3 (including) | 13.3 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.4 (including) | 13.4 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.5 (including) | 13.5 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.6 (including) | 13.6 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.7 (including) | 13.7 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.8 (including) | 13.8 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.9 (including) | 13.9 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.10 (including) | 13.10 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.11 (including) | 13.11 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.12 (including) | 13.12 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 13.13 (including) | 13.13 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24 (including) | 24 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.1 (including) | 24.1 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.2 (including) | 24.2 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.3 (including) | 24.3 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.4 (including) | 24.4 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.5 (including) | 24.5 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.6 (including) | 24.6 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.7 (including) | 24.7 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.8 (including) | 24.8 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.9 (including) | 24.9 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 24.10 (including) | 24.10 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 30 (including) | 30 (including) |
Cloud_foundry_uaa_bosh | Cloudfoundry | 30.1 (including) | 30.1 (including) |
Cloud_foundry_uaa | Pivotal_software | * | 4.2.0 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.2.5.4 (including) | 2.2.5.4 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.1 (including) | 2.7.1 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.2 (including) | 2.7.2 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.3 (including) | 2.7.3 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4 (including) | 2.7.4 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.1 (including) | 2.7.4.1 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.2 (including) | 2.7.4.2 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.3 (including) | 2.7.4.3 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.4 (including) | 2.7.4.4 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.5 (including) | 2.7.4.5 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.6 (including) | 2.7.4.6 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.7 (including) | 2.7.4.7 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.8 (including) | 2.7.4.8 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.9 (including) | 2.7.4.9 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.11 (including) | 2.7.4.11 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.12 (including) | 2.7.4.12 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.13 (including) | 2.7.4.13 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.14 (including) | 2.7.4.14 (including) |
Cloud_foundry_uaa | Pivotal_software | 2.7.4.15 (including) | 2.7.4.15 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.1 (including) | 3.6.1 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.2 (including) | 3.6.2 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.3 (including) | 3.6.3 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.4 (including) | 3.6.4 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.5 (including) | 3.6.5 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.6 (including) | 3.6.6 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.7 (including) | 3.6.7 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.8 (including) | 3.6.8 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.6.9 (including) | 3.6.9 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.1 (including) | 3.9.1 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.2 (including) | 3.9.2 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.3 (including) | 3.9.3 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.4 (including) | 3.9.4 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.5 (including) | 3.9.5 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.6 (including) | 3.9.6 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.7 (including) | 3.9.7 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.8 (including) | 3.9.8 (including) |
Cloud_foundry_uaa | Pivotal_software | 3.9.9 (including) | 3.9.9 (including) |