Vulnerabilities > Cloudfoundry > User Account AND Authentication > 2.3.1.1

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-22001 Unspecified vulnerability in Cloudfoundry Cf-Deployment
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
network
low complexity
cloudfoundry
5.0
2020-02-27 CVE-2020-5402 Cross-Site Request Forgery (CSRF) vulnerability in Cloudfoundry Cf-Deployment
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
6.8
2019-12-06 CVE-2019-11293 Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter.
3.5
2019-11-26 CVE-2019-11290 Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file.
network
low complexity
cloudfoundry CWE-532
7.5
2019-09-26 CVE-2019-11278 Improper Input Validation vulnerability in Cloudfoundry User Account and Authentication
CF UAA versions prior to 74.1.0, allow external input to be directly queried against.
network
low complexity
cloudfoundry CWE-20
7.5
2019-08-09 CVE-2019-11274 Cross-site Scripting vulnerability in Cloudfoundry User Account and Authentication
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack.
4.3
2017-09-07 CVE-2016-0732 Improper Privilege Management vulnerability in multiple products
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
network
low complexity
cloudfoundry pivotal CWE-269
6.5