VDB
CVE-2018-11047
CVE-2018-11047
PUBLISHED
CVSS 7.5 HIGH
Cloud Foundry UAA accepts refresh token as access token on admin endpoints
EPSS 1.07% · 61.6th percentile
Risk Scores
CVSS 3.0
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
1.07%
61.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.cloudfoundry.identity:cloudfoundry-identity-server | 0, 4.6.0, 4.8.0 |
| Cloud Foundry | Cloud Foundry UAA | 4.19, 4.12, 4.5 |
| pivotal_software | cloud_foundry_uaa | 4.5.0, 4.10.0, 4.12.0 |
Timeline
- Jul 24, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://www.cloudfoundry.org/blog/cve-2018-11047/ url
- https://nvd.nist.gov/vuln/detail/CVE-2018-11047 advisory
- https://github.com/cloudfoundry/uaa/commit/0cd3c6fdd96206a1d6a376ac62e21e59e16cdcb1 url
- https://github.com/cloudfoundry/uaa/commit/2906057dae995024576ce6afdc20abd85569514 url
- https://github.com/cloudfoundry/uaa/commit/4cb1be404cf4a82e39cf2a6357aa17af8b33f2a1 url
- https://github.com/cloudfoundry/uaa/commit/4fa3e351ec0bface3b693810605905e29a9a8569 url
- https://github.com/cloudfoundry/uaa/commit/5d021e83ef143c64179d0da015aa76321ee40988 url
- https://github.com/cloudfoundry/uaa/commit/81aeb7a3aa048ea086c494f725d643e48dd9266 url
- https://github.com/cloudfoundry/uaa/commit/a1d523c7f150e56bf06df8b83ed1d416d6c1d3b url
- https://github.com/cloudfoundry/uaa/commit/aba1fb5f18e0d628628b2d960fc6d0cc62d86f5 url
- https://github.com/cloudfoundry/uaa/commit/b37552d2bf084de059bc965b5ef5a45e64883904 url
- https://github.com/cloudfoundry/uaa/commit/bbbba5aec514ad88e7d1e168a2519c80229f02f url
- https://github.com/cloudfoundry/uaa package
- https://www.cloudfoundry.org/blog/cve-2018-11047 url