CVE-2018-15754
13.12.2018, 22:29
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.Enginsight
Vendor | Product | Version |
---|---|---|
pivotal_software | cloud_foundry_uaa-release | 60.0 ≤ 𝑥 < 66.0 |
𝑥
= Vulnerable software versions