CVE-2018-11047
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid refresh token in lieu of an access token. Refresh tokens by design have a longer expiration time than access tokens, allowing the possessor of a refresh token to authenticate longer than expected. This affects the administrative endpoints of the UAA. i.e. /Users, /Groups, etc. However, if the user has been deleted or had groups removed, or the client was deleted, the refresh token will no longer be valid.
Cloud Foundry UAA, en versiones 4.19 anteriores a la 4.19.2, versiones 4.12 anteriores a la 4.12.4, versiones 4.10 anteriores a la 4.10.2, versiones 4.7 anteriores a la 4.7.6 y versiones 4.5 anteriores a la 4.5.7, autoriza incorrectamente las peticiones a los endpoints admin aceptando un token de actualización válido en lugar de un token de acceso. Por diseño, los tokens de actualización tienen un tiempo de expiración mayor que los tokens de acceso, lo que permite que el poseedor de un token de actualización se autentique más tiempo del esperado. Esto afecta a los endpoints administrativos de UAA, p.ej., /Users, /Groups, etc. Sin embargo, si el usuario ha sido eliminado o le han eliminado grupos, o si se ha eliminado el cliente, el token de actualización ya no será válido.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-05-14 CVE Reserved
- 2018-07-24 CVE Published
- 2024-05-27 EPSS Updated
- 2024-09-17 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.cloudfoundry.org/blog/cve-2018-11047 | 2019-10-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.5.0 < 4.5.7 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.5.0 < 4.5.7" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.7.0 < 4.7.6 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.7.0 < 4.7.6" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.10.0 < 4.10.2 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.10.0 < 4.10.2" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.12.0 < 4.12.4 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.12.0 < 4.12.4" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.19.0 < 4.19.2 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.19.0 < 4.19.2" | - |
Affected
|