← Back

Uaa Release

uaa-release

Vendor: Cloudfoundry • 8 CVEs

CVEs (8)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cloudfoundry
2Cf Deployment
Uaa Release
May 10, 2026
Mar 5, 2026
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
1Cloudfoundry
2Cf Deployment
Uaa Release
Jul 11, 2025
May 13, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
1Cloudfoundry
1Uaa Release
Nov 21, 2024
Sep 26, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them...Show more
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.Show less
1Cloudfoundry
3Cf Deployment
CredhubUaa Release
Nov 21, 2024
Apr 25, 2019
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entr...Show more
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.Show less
1Cloudfoundry
1Uaa Release
Nov 21, 2024
Apr 25, 2019
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unau...Show more
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.Show less
1Cloudfoundry
1Uaa Release
Nov 21, 2024
Mar 7, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
1Cloudfoundry
2Cf Release
Uaa Release
May 13, 2026
Nov 27, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows a...Show more
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.Show less
2Cloudfoundry
Pivotal
4Cf Release
Elastic RuntimeUaa Release+1 more
May 13, 2026
Sep 7, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allo...Show more
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.Show less