VDB
CVE-2021-22001
CVE-2021-22001
PUBLISHED
CVSS 7.5 HIGH
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
EPSS 0.99% · 60.9th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.99%
60.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Cloud Foundry UAA server | Cloud Foundry UAA server prior to version 75.3.0 |
| cloudfoundry | cf-deployment | 0 |
| cloudfoundry | user_account_and_authentication | 0 |
Timeline
- Jul 22, 2021 CVE Published
- Jul 23, 2021 EPSS Score
- Sep 21, 2021 EPSS Score
- Nov 20, 2021 EPSS Score
- Jan 19, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 20, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 18, 2022 EPSS Score
- Jul 18, 2022 EPSS Score
- Nov 15, 2022 EPSS Score
- Jan 14, 2023 EPSS Score