CVE-2015-5171Insufficient Session Expiration in Cf-release

Severity
9.8CRITICALNVD
EPSS
0.5%
top 34.72%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 24
Latest updateMay 13

Description

The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

🔴Vulnerability Details

3
OSV
Cloud Foundry Runtime Insufficient Session Expiration vulnerability2022-05-13
GHSA
Cloud Foundry Runtime Insufficient Session Expiration vulnerability2022-05-13
CVEList
CVE-2015-5171: The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 22017-10-24

📄Research Papers

1
arXiv
SeqTrans: Automatic Vulnerability Fix via Sequence to Sequence Learning2022-03-22
CVE-2015-5171 — Insufficient Session Expiration | cvebase