CVE-2021-22001Sensitive Information Exposure in Cf-deployment

Severity
7.5HIGHNVD
EPSS
0.3%
top 44.64%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 22
Latest updateMay 24

Description

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-8f73-86rh-w9fj: In UAA versions prior to 752022-05-24
CVEList
CVE-2021-22001: In UAA versions prior to 752021-07-22
CVE-2021-22001 — Sensitive Information Exposure | cvebase