Vulnerabilities > Cloudfoundry > User Account AND Authentication > High

DATE CVE VULNERABILITY TITLE RISK
2021-07-22 CVE-2021-22001 Unspecified vulnerability in Cloudfoundry User Account and Authentication
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
network
low complexity
cloudfoundry
7.5
2020-02-27 CVE-2020-5402 Cross-Site Request Forgery (CSRF) vulnerability in Cloudfoundry Cf-Deployment
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers.
network
low complexity
cloudfoundry CWE-352
8.8
2019-11-26 CVE-2019-11290 Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file.
network
low complexity
cloudfoundry CWE-532
7.5
2019-09-26 CVE-2019-11278 Unspecified vulnerability in Cloudfoundry User Account and Authentication
CF UAA versions prior to 74.1.0, allow external input to be directly queried against.
network
low complexity
cloudfoundry
8.8
2017-09-07 CVE-2016-0732 Improper Privilege Management vulnerability in multiple products
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
network
low complexity
cloudfoundry pivotal CWE-269
8.8