Cloud Foundry UAA Identity Zone Admin Privilege Escalation
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Mar 1, 2024
Package
Affected versions
< 3.6.13
>= 3.7.0, < 3.9.15
>= 3.10.0, < 3.20.0
>= 4.0.0, < 4.4.0
Patched versions
3.6.13
3.9.15
3.20.0
4.4.0
Description
Published by the National Vulnerability Database
Jul 10, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Mar 1, 2024
Last updated
Mar 1, 2024
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to v24.12. 30.x versions prior to 30.5, and other versions prior to v41, zone administrators are allowed to escalate their privileges when mapping permissions for an external provider.
References