VDB

CVE-2021-22001

CVE-2021-22001 PUBLISHED CVSS 7.5 HIGH

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.

EPSS 0.99% · 60.9th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.99%
60.9th percentile

Affected Products

VendorProductVersions
n/aCloud Foundry UAA serverCloud Foundry UAA server prior to version 75.3.0
cloudfoundrycf-deployment0
cloudfoundryuser_account_and_authentication0

Timeline

  • Jul 22, 2021 CVE Published
  • Jul 23, 2021 EPSS Score
  • Sep 21, 2021 EPSS Score
  • Nov 20, 2021 EPSS Score
  • Jan 19, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 20, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 18, 2022 EPSS Score
  • Jul 18, 2022 EPSS Score
  • Nov 15, 2022 EPSS Score
  • Jan 14, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›