CVE-2018-1192
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.
En Cloud Foundry Foundation cf-release en versiones anteriores a v285; cf-deployment anteriores a v1.7; UAA 4.5.x anteriores a 4.5.5, 4.8.x anteriores a 4.8.3 y 4.7.x anteriores a 4.7.4 y UAA-release 45.7.x anteriores a 45.7, 52.7.x anteriores a 52.7 y 53.3.x anteriores a 53.3, SessionID se registra en los logs de eventos de auditoría. Un atacante podría utilizar el SessionID para suplantar un usuario registrado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-06 CVE Reserved
- 2018-02-01 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.cloudfoundry.org/blog/cve-2018-1192 | 2018-02-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.5.0 < 4.5.5 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.5.0 < 4.5.5" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.7.0 < 4.7.4 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.7.0 < 4.7.4" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" | >= 4.8.0 < 4.8.3 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa" and version " >= 4.8.0 < 4.8.3" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa-release Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" | 45.7 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" and version "45.7" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa-release Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" | 52.7 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" and version "52.7" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Uaa-release Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" | 53.3 Search vendor "Pivotal Software" for product "Cloud Foundry Uaa-release" and version "53.3" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Cf-release Search vendor "Pivotal Software" for product "Cloud Foundry Cf-release" | < 285 Search vendor "Pivotal Software" for product "Cloud Foundry Cf-release" and version " < 285" | - |
Affected
| ||||||
Pivotal Software Search vendor "Pivotal Software" | Cloud Foundry Cf-deployment Search vendor "Pivotal Software" for product "Cloud Foundry Cf-deployment" | < 1.7 Search vendor "Pivotal Software" for product "Cloud Foundry Cf-deployment" and version " < 1.7" | - |
Affected
|