CVE Vulnerabilities

CVE-2018-1262

Published: May 15, 2018 | Modified: Aug 17, 2021
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

Affected Software

Name Vendor Start Version End Version
Cloud_foundry_uaa Pivotal_software 4.12.0 (including) 4.12.0 (including)
Cloud_foundry_uaa Pivotal_software 4.12.1 (including) 4.12.1 (including)
Cloud_foundry_uaa Pivotal_software 4.12.2 (including) 4.12.2 (including)
Cloud_foundry_uaa Pivotal_software 4.13.0 (including) 4.13.0 (including)
Cloud_foundry_uaa Pivotal_software 4.13.1 (including) 4.13.1 (including)
Cloud_foundry_uaa Pivotal_software 4.13.2 (including) 4.13.2 (including)
Cloud_foundry_uaa Pivotal_software 4.13.3 (including) 4.13.3 (including)
Cloud_foundry_uaa Pivotal_software 4.13.4 (including) 4.13.4 (including)

References