CVE-2015-3189Weak Password Recovery Mechanism for Forgotten Password in Cf-release

Severity
3.7LOWNVD
EPSS
0.2%
top 60.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 25
Latest updateMay 13

Description

With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.2 | Impact: 1.4

Affected Packages4 packages

CVEListV5pivotal/cloud_foundryRuntime 1.4.5 or earlier, Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier+2

🔴Vulnerability Details

3
GHSA
Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password2022-05-13
OSV
Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password2022-05-13
CVEList
CVE-2015-3189: With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 22017-05-25
CVE-2015-3189 — Cloudfoundry Cf-release vulnerability | cvebase