CVE-2018-15754

MEDIUM

Cloud Foundry UAA 60.0-65.x - Authenticated Incorrect Authorization via Identity Provider Username Collision

Title source: llm
STIX 2.1

Description

Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/106240
Mitigation, Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2018-15754/
Mitigation, Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2018-15754

Scores

CVSS v3 4.2
EPSS 0.0178
EPSS Percentile 75.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Details

CWE
CWE-863
Status published
Products (1)
pivotal_software/cloud_foundry_uaa-release 60.0 - 66.0
Published Dec 13, 2018
Tracked Since Feb 18, 2026