Vulnerability CVE-2018-11082


Published: 2018-10-05

Description:
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

Type:

CWE-255

(Credentials Management)

Vendor: Pivotal software
Product: Cloudfoundry uaa release 
Version:
9
8
7
60.2
60
6
59
58.1
58
57.4
57.3
57.2
57.1
57
56
55.2
55.1
55
54
53.3
53.2
53.1
53
52.9
52.8
52.7
52.6
52.5
52.4
52.2
52.10
52
51
50
5
48
45.9
45.8
45.7
45.6
45.5
45.4
45.3
45.2
45.11
45.10
45
44
43
41.1
41
40
4
39
38
37
36
35
34.3
34.2
34.1
34
33
32
31
30.9
30.8
30.7
30.6
30.5
30.4
30.3
30.2
30.1
30
3
29
28
27
26
25
24.9
See more versions on NVD
Product: Cloudfoundry uaa 
Version:
4.7.6
4.5.7
4.19.2
4.12.4
4.12.3
4.10.2
3.4.2
3.4.1
3.4.0
3.3.0.1
3.3.0
3.2.1
3.2.0
3.1.0
3.0.1
3.0.0
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://www.cloudfoundry.org/blog/cve-2018-11082/

Related CVE
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...
CVE-2019-3787
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending ?unknown.org? to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack v...
CVE-2019-11269
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicio...
CVE-2019-3790
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user c...
CVE-2019-3795
Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an ...
CVE-2019-3792
Pivotal Concourse version 5.0.0, contains an API that is vulnerable to SQL injection. An Concourse resource can craft a version identifier that can carry a SQL injection payload to the Concourse server, allowing the attacker to read privileged data.
CVE-2019-3778
Spring Security OAuth, versions 2.3 prior to 2.3.5, and 2.2 prior to 2.2.4, and 2.1 prior to 2.1.4, and 2.0 prior to 2.0.17, and older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malic...
CVE-2019-3776
Pivotal Operations Manager, 2.1.x versions prior to 2.1.20, 2.2.x versions prior to 2.2.16, 2.3.x versions prior to 2.3.10, 2.4.x versions prior to 2.4.3, contains a reflected cross site scripting vulnerability. A remote user that is able to convince...

Copyright 2019, cxsecurity.com

 

Back to Top