Cloudfoundry User Account And Authentication vulnerabilities

8 known vulnerabilities affecting cloudfoundry/user_account_and_authentication.

Total CVEs
8
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2021-22098MEDIUMCVSS 6.1fixed in 75.5.02021-08-11
CVE-2021-22098 [MEDIUM] CWE-601 CVE-2021-22098: UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious us UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites.
nvd
CVE-2021-22001HIGHCVSS 7.5fixed in 75.3.02021-07-22
CVE-2021-22001 [HIGH] CWE-200 CVE-2021-22001: In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was reve In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
nvd
CVE-2020-5402HIGHCVSS 8.8fixed in 74.14.02020-02-27
CVE-2020-5402 [HIGH] CWE-352 CVE-2020-5402: In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
nvd
CVE-2019-11293MEDIUMCVSS 6.5fixed in 74.10.02019-12-06
CVE-2019-11293 [MEDIUM] CWE-532 CVE-2019-11293: Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_ Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
nvd
CVE-2019-11290HIGHCVSS 7.5fixed in 74.8.02019-11-26
CVE-2019-11290 [HIGH] CWE-532 CVE-2019-11290: Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access f Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
nvd
CVE-2019-11278HIGHCVSS 8.8fixed in 74.1.02019-09-26
CVE-2019-11278 [HIGH] CWE-77 CVE-2019-11278: CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malic CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
nvd
CVE-2019-11274MEDIUMCVSS 6.1fixed in 74.0.02019-08-09
CVE-2019-11274 [MEDIUM] CWE-79 CVE-2019-11274: Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticate Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
nvd
CVE-2016-0732HIGHCVSS 8.8v2.0.0v2.0.1+31 more2017-09-07
CVE-2016-0732 [HIGH] CWE-269 CVE-2016-0732: The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0 The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified
nvd