VDB
CVE-2018-1262
CVE-2018-1262
PUBLISHED
CVSS 6.5 MEDIUM
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.
EPSS 1.34% · 68.6th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
1.34%
68.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| pivotal_software | cloud_foundry_uaa | 4.13.4, 4.12.0, 4.12.1 |
| Cloud Foundry | CloudFoundry UAA | 4.12.X and 4.13.X |
| pivotal_software | cloud_foundry_uaa-release | 57.1, 58, 57 |
| Maven | org.cloudfoundry.identity:cloudfoundry-identity-server | 4.13.0, 4.12.0 |
| cloudfoundry | cf-deployment | 1.27.0 |
Timeline
- May 15, 2018 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2018-1262 advisory
- https://github.com/cloudfoundry/uaa/commit/14c745aa293b8d3ce9cdd6bfbc6c0ef3f269b21 url
- https://github.com/cloudfoundry/uaa/commit/dccd3962f969913996ee88f653fce3b108c0205 url
- https://github.com/cloudfoundry/uaa package
- https://www.cloudfoundry.org/blog/cve-2018-1262 url
- https://www.cloudfoundry.org/blog/cve-2018-1262/ advisory