Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1mbTVjLTJyd2MtODg3d83t7A
Cloud Foundry UAA reset password vulnerable to brute force attack
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given time. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected.
Permalink: https://github.com/advisories/GHSA-fm5c-2rwc-887wJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1mbTVjLTJyd2MtODg3d83t7A
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: over 2 years ago
Updated: 11 months ago
CVSS Score: 8.1
CVSS vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Percentage: 0.00228
EPSS Percentile: 0.6057
Identifiers: GHSA-fm5c-2rwc-887w, CVE-2016-3084
References:
- https://nvd.nist.gov/vuln/detail/CVE-2016-3084
- https://pivotal.io/security/cve-2016-3084
- https://github.com/cloudfoundry/uaa/commit/14350228989e2aee900b8d48a848293bb5152b6f
- https://github.com/cloudfoundry/uaa/commit/1d3ad7399d010f6a29dc3bf8139d792121301ab8
- https://github.com/cloudfoundry/uaa/commit/460627ed419e4227b10ff121248b3ffc009011a9
- https://github.com/cloudfoundry/uaa/commit/4a119d314744460ed56bcd740b2e913bf3f560c1
- https://github.com/cloudfoundry/uaa/commit/5c2377487bef9d716d5c8e5717df1fc00bc7b000
- https://github.com/cloudfoundry/uaa/commit/66132926f1bac0b878da5841be2f93fa5075d88f
- https://github.com/cloudfoundry/uaa/commit/b3834364ab573e9655348193780a56a602fe87b7
- https://github.com/advisories/GHSA-fm5c-2rwc-887w
Blast Radius: 9.5
Affected Packages
maven:org.cloudfoundry.identity:cloudfoundry-identity-server
Dependent packages: 3Dependent repositories: 15
Downloads:
Affected Version Ranges: < 3.3.0.1
Fixed in: 3.3.0.1
All affected versions:
All unaffected versions: 3.0.0, 3.0.1, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.4.0, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.5.0, 3.6.0, 3.7.0, 3.7.3, 3.8.0, 3.9.0, 3.9.1, 3.10.0, 3.12.0, 3.13.0, 3.15.0, 3.16.0, 3.18.0, 3.19.0, 3.20.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.5.6, 4.5.7, 4.5.8, 4.5.9, 4.6.0, 4.6.1, 4.7.0, 4.7.1, 4.7.2, 4.7.4, 4.7.5, 4.7.6, 4.8.0, 4.8.2, 4.8.3, 4.9.0, 4.10.0, 4.10.1, 4.10.2, 4.11.0, 4.12.0, 4.12.1, 4.12.2, 4.12.3, 4.12.4, 4.13.0, 4.13.1, 4.13.3, 4.13.4, 4.14.0, 4.15.0, 4.16.0, 4.17.0, 4.18.0, 4.19.0, 4.19.2, 4.20.0, 4.21.0, 4.22.0, 4.23.0, 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.30.0