Back to overview

CVE-2018-15761

CRITICAL
9.9
CVSS 3.0
Description
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.

Metadata

CVE ID
CVE-2018-15761
State
PUBLISHED
Assigner
dell
Reserved
2018-08-23 00:00 UTC
Published
2018-11-19 14:00 UTC
Last updated
2024-09-17 00:46 UTC
Vendor / Product
Cloud Foundry / UAA
Sources
cve.org  ·  NVD

Severity & Metrics

9.9 CRITICAL CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Affected products (2)
VendorProductPlatformVersions
Cloud Foundry UAA all versions < 4.23.0
Cloud Foundry UAA Release all versions < 64.0
Weakness (CWE)
CWESourceDescription
cna Improper Access Control
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.9 CRITICAL 3.0 cna CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Back to overview