Privilege Escalation Vulnerability in Cloud Foundry UAA
CVE-2018-1262
7.2HIGH
What is CVE-2018-1262?
In versions 4.12.X and 4.13.X of Cloud Foundry UAA, a vulnerability was introduced that allows for potential privilege escalation across identity zones. This occurs when a zone administrator configures their zone to issue tokens capable of impersonating another zone. As a result, clients conducting offline token validation may gain admin privileges in an impersonated zone, leading to unauthorized access and potential security breaches.
Affected Version(s)
CloudFoundry UAA 4.12.X and 4.13.X
