VDB

CVE-2023-20903

CVE-2023-20903 PUBLISHED CVSS 8.600000381469727 HIGH

This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider from the UAA. It is expected that the UAA would reject a refresh token during a refresh token grant, but it does not (hence the vulnerability). It will continue to issue access tokens to request presenting such refresh tokens, as if the identity provider was still active. As a result, clients with refresh tokens issued through the deactivated identity provider would still have access to Cloud Foundry resources until their refresh token expires (which defaults to 30 days).

EPSS 0.40% · 33.3th percentile

Risk Scores

CVSS 4.0
8.600000381469727
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.40%
33.3th percentile

Affected Products

VendorProductVersions
cloudfoundryuser_account_and_authentication
n/aCloud Foundry*, *

Timeline

  • Mar 28, 2023 CVE Published
  • Mar 29, 2023 EPSS Score
  • May 6, 2023 EPSS Score
  • Jun 13, 2023 EPSS Score
  • Jul 22, 2023 EPSS Score
  • Aug 29, 2023 EPSS Score
  • Oct 6, 2023 EPSS Score
  • Nov 13, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
  • Jan 29, 2024 EPSS Score
  • Mar 7, 2024 EPSS Score
  • Apr 14, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›