Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

UAA Privilege Escalation

Disclosure Date: November 19, 2018 (last updated November 27, 2024)
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
0
Attacker Value
Unknown

Cloud Foundry UAA MFA does not prevent brute force of MFA code

Disclosure Date: October 05, 2018 (last updated November 27, 2024)
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
0