CVE Database
/

CVE-2018-1262

Back to search

CVE-2018-1262

Published: May 15, 2018

Modified: Sep 16, 2024

PUBLISHED

Description

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

VendorProductVersions

Cloud Foundry

CloudFoundry UAA

affected
4.12.X and 4.13.X

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now