Cloudfoundry Uaa Release vulnerabilities
5 known vulnerabilities affecting cloudfoundry/uaa_release.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2025-22246HIGHCVSS 7.5≥ 77.21.0, < 77.32.02025-05-13
CVE-2025-22246 [HIGH] CWE-532 CVE-2025-22246: Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
nvd
CVE-2019-11279HIGHCVSS 8.8fixed in 74.1.02019-09-26
CVE-2019-11279 [HIGH] CWE-77 CVE-2019-11279: CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitt
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.
nvd
CVE-2019-3801CRITICALCVSS 9.8fixed in 64.02019-04-25
CVE-2019-3801 [CRITICAL] CWE-494 CVE-2019-3801: Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an inse
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
nvd
CVE-2019-3788MEDIUMCVSS 6.1fixed in 71.02019-04-25
CVE-2019-3788 [MEDIUM] CWE-601 CVE-2019-3788: Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.
nvd
CVE-2019-3775MEDIUMCVSS 6.5fixed in 70.02019-03-07
CVE-2019-3775 [MEDIUM] CWE-290 CVE-2019-3775: Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remot
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
nvd