Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) before 13.9 for UAA 3.6.5 and before 24 for UAA 3.9.3 allow attackers to gain privileges by accessing UAA logs and subsequently running a specially crafted application that interacts with a configured SAML provider.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:*"
],
"vendor_product": "cloudfoundry:cloud_foundry_uaa_bosh",
"extracted_events": [
{
"last_affected": "23.0"
}
]
},
{
"extracted_events": [
{
"last_affected": "247.0"
}
],
"cpes": [
"cpe:2.3:a:pivotal_software:cloud_foundry:*:*:*:*:*:*:*:*"
],
"vendor_product": "pivotal_software:cloud_foundry",
"source": "CPE_RANGE"
}
]
}{
"cpe": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*",
"source": "CPE_RANGE",
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.9.2"
}
]
}