6.5
CVSSv2

CVE-2018-1262

Published: 15/05/2018 Updated: 17/08/2021
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software cloud foundry uaa 4.13.2

pivotal software cloud foundry uaa 4.13.3

pivotal software cloud foundry uaa 4.13.1

pivotal software cloud foundry uaa 4.12.1

pivotal software cloud foundry uaa 4.13.4

pivotal software cloud foundry uaa 4.12.0

pivotal software cloud foundry uaa 4.13.0

pivotal software cloud foundry uaa 4.12.2

pivotal software cloud foundry uaa-release 57.1

pivotal software cloud foundry uaa-release 58

pivotal software cloud foundry uaa-release 57

cloudfoundry cf-deployment