CVE-2018-15761: UAA Privilege Escalation
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-15761?
CVE-2018-15761 is a vulnerability in Cloud Foundry UAA and UAA release versions that allows for privilege escalation.
What is the severity of CVE-2018-15761?
CVE-2018-15761 has a severity rating of 8.8 (critical).
Which software versions are affected by CVE-2018-15761?
Cloud Foundry UAA versions prior to 4.23.0 and UAA release versions prior to v64.0 are affected by CVE-2018-15761.
How can the privilege escalation be exploited in CVE-2018-15761?
A remote authenticated user can modify the consent page URL and content to gain a token with arbitrary scopes, thereby escalating their privileges.
Where can I find more information about CVE-2018-15761?
You can find more information about CVE-2018-15761 at the following link: https://www.cloudfoundry.org/blog/cve-2018-15761/