GHSA-j4p3-2m2h-cv5f

Suggest an improvement
Source
https://github.com/advisories/GHSA-j4p3-2m2h-cv5f
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j4p3-2m2h-cv5f/GHSA-j4p3-2m2h-cv5f.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j4p3-2m2h-cv5f
Aliases
Published
2022-05-13T01:10:00Z
Modified
2024-12-07T06:07:52.232532Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Cloud Foundry UAA Denial of Service through client token revocation endpoint
Details

An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.

Database specific
{
    "nvd_published_at": "2017-11-27T10:29:00Z",
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-03-01T20:07:31Z"
}
References

Affected packages

Maven / org.cloudfoundry.identity:cloudfoundry-identity-server

Package

Name
org.cloudfoundry.identity:cloudfoundry-identity-server
View open source insights on deps.dev
Purl
pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
4.7.1

Affected versions

4.*

4.6.0
4.6.1
4.7.0

Maven / org.cloudfoundry.identity:cloudfoundry-identity-server

Package

Name
org.cloudfoundry.identity:cloudfoundry-identity-server
View open source insights on deps.dev
Purl
pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Fixed
4.5.3

Affected versions

4.*

4.1.0
4.2.0
4.3.0
4.4.0
4.5.0

Maven / org.cloudfoundry.identity:cloudfoundry-identity-server

Package

Name
org.cloudfoundry.identity:cloudfoundry-identity-server
View open source insights on deps.dev
Purl
pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20.1

Affected versions

3.*

3.0.0
3.0.1
3.1.0
3.2.0
3.2.1
3.3.0
3.3.0.1
3.3.0.2
3.3.0.3
3.3.0.4
3.3.0.5
3.4.0
3.4.2
3.4.3
3.4.4
3.4.5
3.5.0
3.6.0
3.7.0
3.7.3
3.8.0
3.9.0
3.9.1
3.10.0
3.12.0
3.13.0
3.15.0
3.16.0
3.18.0
3.19.0
3.20.0