Cloud Foundry vulnerable to Improper Certificate Validation
Moderate severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 28, 2024
Package
Affected versions
>= 3.0.0, < 3.3.0.3
>= 3.4.0, < 3.4.2
Patched versions
3.3.0.3
3.4.2
Description
Published by the National Vulnerability Database
Apr 24, 2017
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 28, 2024
Last updated
Feb 28, 2024
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
References