CVE-2024-38806
3.9
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Exploitability: 0.5 / Impact: 3.4
Source: security@vmware.com (Secondary)
Description
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 ,
potentially resulting in users retaining access rights they should not
have. This can allow them to perform operations beyond their intended
permissions.
References (2)
Source: security@vmware.com
Source: af854a3a-2127-422b-91ae-364da2661108
Timeline
No history available yet.