Cloud Foundry UAA
cpe:2.3:a:cloudfoundry:uaa:*:*:*:*:*:*:*
- <= 77.20.1
- <= 77.24.0
- = 77.21.0
- = 77.22.0
- = 77.23.0
A vulnerability exists in Cloud Foundry UAA versions through 77.20.1 and 77.24.0, excluding releases 77.20.2 and 77.25.0. The issue arises in UAA instances configured with multiple identity zones, where session information is not properly validated across those zones. This flaw allows a user authenticated against a corporate identity provider to reuse their session ID to access other zones, potentially leading to unauthorized access.
Exploitation of this vulnerability could result in unauthorized access to different identity zones within the UAA, allowing users to bypass zone-specific authentication requirements.
Users can upgrade to UAA version 77.20.2 or higher, or to version 77.25.0 or higher.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.