CVE-2018-15754
In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.78%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-863
- Affected
- pivotal software/cloud foundry uaa-release
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/106240Third Party Advisory, VDB Entry
- https://www.cloudfoundry.org/blog/cve-2018-15754Mitigation, Vendor Advisory
- https://www.cloudfoundry.org/blog/cve-2018-15754/Mitigation, Vendor Advisory
- http://www.securityfocus.com/bid/106240Third Party Advisory, VDB Entry
- https://www.cloudfoundry.org/blog/cve-2018-15754Mitigation, Vendor Advisory
- https://www.cloudfoundry.org/blog/cve-2018-15754/Mitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.