CVE-2018-11082: Cloud Foundry UAA MFA does not prevent brute force of MFA code
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11082?
CVE-2018-11082 is a vulnerability in Cloud Foundry UAA and Cloud Foundry UAA Release that allows brute forcing of MFA codes.
What is the severity of CVE-2018-11082?
The severity of CVE-2018-11082 is critical with a severity value of 9.8.
How does CVE-2018-11082 affect Cloud Foundry UAA?
CVE-2018-11082 affects all versions of Cloud Foundry UAA prior to 4.20.0.
How does CVE-2018-11082 affect Cloud Foundry UAA Release?
CVE-2018-11082 affects all versions of Cloud Foundry UAA Release prior to 61.0.
How can the brute forcing of MFA codes be prevented for CVE-2018-11082?
To prevent the brute forcing of MFA codes for CVE-2018-11082, it is recommended to upgrade to Cloud Foundry UAA 4.20.0 or later and Cloud Foundry UAA Release 61.0 or later.