Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2018-12-13T22:00:00Z
Updated: 2024-09-16T17:24:01.117Z
Reserved: 2018-08-23T00:00:00
Link: CVE-2018-15754
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-12-13T22:29:00.280
Modified: 2019-10-09T23:35:51.250
Link: CVE-2018-15754
Redhat
No data.