Cloud Foundry UAA and Deployment Inappropriate User Token Revocation Vulnerability

Vulnerability

A logic error in the token revocation endpoint has led to inappropriate user token revocation in Cloud Foundry UAA versions 77.30.0 prior to 78.7.0, and in Cloud Foundry Deployment versions 48.7.0 prior to 54.10.0.

Impact

This vulnerability can lead to improper management of user tokens, potentially allowing for unauthorized access or actions on behalf of a user.

Remediation

Users are advised to upgrade Cloud Foundry UAA to version 78.8.0 or greater, and to upgrade Cloud Foundry Deployment to version 54.11.0 or greater, which includes UAA version 78.8.0.

Added: Mar 5, 2026, 9:21 PM
Updated: Mar 5, 2026, 9:21 PM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.3
exploitability
5.4
remediation
7.7
relevance
3.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.